Clarifying facts on device monitoring, and collecting your preference on ERP mobile access and corporate communication numbers.
Following recent security incidents on the Archcorp domain, Archcorp is re-evaluating the scope of provided mobile devices and moving business communications off personal devices. This survey is part of that audit.
Archcorp has faced multiple security issues on the Archcorp domain. In response, Archcorp is re-evaluating the scope of providing mobile devices, and is working to remove business communications from personal devices wherever a genuine alternative can be provided. As part of this, Archcorp is taking active steps to ensure that personal data, passwords, files, and applications are not accessible to any individual, on any device.
This survey is Archcorp-recommended and serves two purposes: first, to confirm your understanding of the security tools Archcorp currently uses, and give clarity to any user unsure whether a security tool installed on their device means it is being tracked. Second, your responses form part of Archcorp's audit of personal device usage and record your agreement with Archcorp's personal device usage policy going forward.
Several colleagues raised concern that installing Archcorp-related applications (Microsoft Authenticator, Teams, Outlook, Archcorp ERP) on personal phones means Archcorp can track their personal device, location, or activity. This is not true. Archcorp's security stack — MDM, PAM, XDR/EDR, Hexnode, Accops, Checkpoint, Sentinel and Microsoft Entra — is scoped to monitor corporate identities, corporate accounts, and corporate-owned devices only, in line with UAE cyber law. Below is a plain breakdown of fact vs. myth, followed by the architecture diagram, the survey, and the checklist used to plan next steps (including corporate SIMs/phones and WhatsApp Business numbers).
"If I install Authenticator / Teams / ERP on my personal phone, Archcorp can see my personal apps, photos, or location history."
These apps only manage the corporate account container. Archcorp cannot see personal apps, personal photos, personal browsing, or GPS location of a personal device.
"Security tools like MDM/PAM/Hexnode monitor me personally, all the time."
MDM/Hexnode policies apply only where BYOD enrollment is business-mandated (case-by-case). PAM & Accops govern privileged/remote access sessions on corporate systems — not personal device usage.
"Sign-in tracking is something unique/invasive that Archcorp built."
Sign-in location/device logging (via Microsoft Entra) is standard for every Microsoft 365, Google Workspace, or similar tenant worldwide — it protects your account from compromise, not the other way around.
"Corporate devices and personal devices are treated the same."
Corporate-owned devices (desktop/laptop issued to every staff member) are fully managed and monitored for security compliance. Personal devices are not monitored unless a specific BYOD business case is approved.
As part of ongoing compliance, DLP (Data Loss Prevention) now covers corporate-device activity such as file transfers between personal and corporate storage and use of unprotected/weak passwords, and Teramind provides activity oversight on corporate devices for compliance purposes. This applies to corporate systems and corporate device activity — not to personal-device content.