<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

X-ray of a Successful Enterprise Digital Workplace Strategy

Reviewed and updated in October 2026.

Following our look at a small business digital workplace strategy, part two moves up a size. Our case study is two enterprise organizations: one on the US East Coast with a couple of hundred employees, the other of similar size with several offices along the West Coast.

An enterprise digital workplace strategy connects people, devices, data and security across several teams and sites. It defines which ownership model applies to which devices, how employees reach data in the data center and in SaaS applications, how devices and data are protected, and who in IT, security and mobility is responsible for what. Its aim is one consistent experience and one security standard instead of a separate setup for every office.

The enterprise scenario

Like many organizations during the pandemic, both companies had most employees working remotely, with a few in the office. Each has its own IT team, uses company-owned desktop and laptop computers as main work devices and mobile devices when needed.

Which challenges did they need to address?

Like most organizations before COVID, both had a digital workspace somewhere on their roadmap, but no plan for rolling it out overnight. Fortunately, they had already started reviewing their digital workplace needs and could accelerate the rollout.

  • Access to corporate data: data lives in their own data centers and in SaaS applications such as CRM and ticketing. With a hybrid workforce that is mostly remote and mobile, access from mobile devices added complexity.
  • Protecting devices: every device processes and may store business-critical data, so it has to be protected against cyberattacks and unintentional data leaks.
  • Teams working together: IT and network, security and mobility teams had to enforce one strategy while each stayed responsible for its own area.

How did they address these challenges?

Ownership models for mobile devices

The strategy was built around the ownership model of the devices. Laptops, the primary devices, were corporate owned, business only (COBO). Mobile devices fell into one of two categories, depending on job requirements:

  • COPE (Corporate Owned, Personally Enabled) for users who need access to sensitive corporate data on the go.
  • BYOD (Bring Your Own Device) for users who do not strictly need mobile access but benefit from it.

COPE devices were fully managed by IT to enforce stronger security controls, while leaving room for personal apps and documents. They arrived fully enrolled, configured and provisioned with all required work apps and a dedicated work number with a data plan, provisioned via eSIM. Because the devices support multiple SIMs, employees could add their personal subscription and make private calls with their own number without carrying two devices.

BYOD was allowed for devices on a curated list of tested and approved models defined by IT, to ensure security, compatibility and a smooth user experience. These devices were partially managed: a device passcode and a minimum security level were required, and only work apps and data were controlled. Personal apps and documents were neither managed nor visible to the company. For work calls with a dedicated number at no cost to the employee, the company provided a voice and video over IP subscription, as an app or integrated into the operating system, depending on manufacturer and model.

Desktop devices and virtual desktops

Heavy, underperforming workstations were replaced with lightweight endpoints such as Chromebooks, a cost-effective alternative that accesses business apps through on-premises or SaaS virtual desktop infrastructure (VDI). The desktop runs in the back end, so corporate data does not leave it. More on the concept in Demystifying Technology: Virtualization Beyond Servers and on ChromeOS in our ChromeOS solution highlight.

How was sensitive work data handled and stored?

Ideally, work data is never stored on an employee device, mobile or desktop, personal or corporate. Where it is, data leaks must be prevented.

On BYOD devices, app containerization kept work data secured and separated from the rest of the device. For Microsoft 365 apps, Intune app protection policies provide this: a PIN or biometrics can be required to open the apps, and data can only be exchanged between them or with other authorized apps. Only enrolled personal devices that met all security requirements, such as OS and patch level and passcode, could access corporate resources. If a device was lost or stolen, IT could take action, for example blocking or wiping work apps and documents without touching the rest of the device.

On COPE devices, Android devices were separated at operating system level with the Android Enterprise work profile, giving users two clearly distinct spaces for personal and work. On iOS, separation works at app level, with managed apps and restrictions on data sharing between managed and unmanaged apps. On both platforms, a secure repository such as OneDrive or SharePoint, on premises or in the cloud, was enforced for work documents.

How did employees access data?

The enterprises ran a hybrid environment, a mix of on-site and cloud services. Most services, including email, instant messaging and storage for non-sensitive documents, were in the cloud and reachable from anywhere with an internet connection. Multi-factor authentication (MFA) strengthened the sign-in, with a prompt on a registered mobile device whenever a user accessed a sensitive resource. Today, phishing-resistant methods such as passkeys are the better choice than simple push approvals.

For privacy and security reasons, some sensitive information, such as customer data, and some services, such as in-house app development and the related intellectual property, could not move to the cloud. Reaching these resources from outside the office, whether from a home office, an airport or a customer site, is harder. A virtual private network (VPN) provided the secure end-to-end connection between employee devices and the internal network, and most employees already knew how to use it. How a Zero Trust approach can extend this is covered in part three.

How did IT manage it all?

The mobile fleet was managed with a UEM solution, which any business running a digital workplace needs to keep its assets under control. A UEM deploys apps, provides access to corporate resources, enforces security policies and takes action when a device is at risk or non-compliant. A monitoring solution gave a real-time overview of the health of all assets, detected potential issues and helped forecast capacity needs, such as upgrading endpoints or back-end infrastructure.

With more people working from home, cyberattacks increased, so the focus shifted to protecting all endpoints and the business-critical data on them with next-generation antivirus based on behavior-based security. Today this is typically part of endpoint detection and response (EDR), explained in EPP, EDR and MTD.

How did they avoid IT silos?

Both offices had their own local IT teams, so ownership was defined to avoid silos, where divisions, offices, regions or countries operate independently and do not share information. In very specific cases that can be justified, but in general it is inefficient: it leads to as many IT infrastructures as there are silos, which means higher total cost of ownership, a poorer user experience, more complex daily administration and a weaker response to security challenges. A unified strategy that combines assets wherever possible, while respecting genuine local requirements, is the better choice.

Why training decides adoption

A digital workplace strategy is only as good as its adoption, and that requires understanding and commitment, which come through training. Employees need to understand the security concerns and their own responsibility when handling sensitive customer and business data. Balancing security and usability is what makes the strategy succeed. Part three, X-ray of a Successful Global Enterprise Digital Workplace Strategy, adds data residency, compliance and Zero Trust across countries.

Frequently asked questions

What does an enterprise digital workplace strategy include?

It covers device ownership models, access to on-premises and cloud data, protection of devices and data, endpoint management and monitoring, clear responsibilities across IT, security and mobility teams, and training for employees.

Should an enterprise choose COPE or BYOD?

Often both. COPE suits employees who need mobile access to sensitive data, because IT can enforce stronger controls. BYOD with app containerization suits employees for whom mobile access is useful but not essential.

Is a VPN still needed when most services are in the cloud?

For resources that stay on premises, remote access needs a secure connection, and a VPN is a common way to provide it. Zero Trust Network Access (ZTNA) is an alternative that grants access per application based on identity and device state.

Why should IT silos between offices be avoided?

Separate infrastructures for each office raise total cost of ownership, make daily administration more complex and weaken the response to security incidents. A unified strategy with clearly defined ownership keeps one standard while leaving room for local requirements.

Planning or reworking your enterprise digital workplace? Our team supports endpoint management and endpoint security across the major platforms, and ISEC7 SPHERE monitors your digital workplace infrastructure in one console. Contact us with any questions.