Reviewed and updated in October 2026.
Following our look at a small business digital workplace strategy, part two moves up a size. Our case study is two enterprise organizations: one on the US East Coast with a couple of hundred employees, the other of similar size with several offices along the West Coast.
An enterprise digital workplace strategy connects people, devices, data and security across several teams and sites. It defines which ownership model applies to which devices, how employees reach data in the data center and in SaaS applications, how devices and data are protected, and who in IT, security and mobility is responsible for what. Its aim is one consistent experience and one security standard instead of a separate setup for every office.
Like many organizations during the pandemic, both companies had most employees working remotely, with a few in the office. Each has its own IT team, uses company-owned desktop and laptop computers as main work devices and mobile devices when needed.
Like most organizations before COVID, both had a digital workspace somewhere on their roadmap, but no plan for rolling it out overnight. Fortunately, they had already started reviewing their digital workplace needs and could accelerate the rollout.
The strategy was built around the ownership model of the devices. Laptops, the primary devices, were corporate owned, business only (COBO). Mobile devices fell into one of two categories, depending on job requirements:
COPE devices were fully managed by IT to enforce stronger security controls, while leaving room for personal apps and documents. They arrived fully enrolled, configured and provisioned with all required work apps and a dedicated work number with a data plan, provisioned via eSIM. Because the devices support multiple SIMs, employees could add their personal subscription and make private calls with their own number without carrying two devices.
BYOD was allowed for devices on a curated list of tested and approved models defined by IT, to ensure security, compatibility and a smooth user experience. These devices were partially managed: a device passcode and a minimum security level were required, and only work apps and data were controlled. Personal apps and documents were neither managed nor visible to the company. For work calls with a dedicated number at no cost to the employee, the company provided a voice and video over IP subscription, as an app or integrated into the operating system, depending on manufacturer and model.
Heavy, underperforming workstations were replaced with lightweight endpoints such as Chromebooks, a cost-effective alternative that accesses business apps through on-premises or SaaS virtual desktop infrastructure (VDI). The desktop runs in the back end, so corporate data does not leave it. More on the concept in Demystifying Technology: Virtualization Beyond Servers and on ChromeOS in our ChromeOS solution highlight.
Ideally, work data is never stored on an employee device, mobile or desktop, personal or corporate. Where it is, data leaks must be prevented.
On BYOD devices, app containerization kept work data secured and separated from the rest of the device. For Microsoft 365 apps, Intune app protection policies provide this: a PIN or biometrics can be required to open the apps, and data can only be exchanged between them or with other authorized apps. Only enrolled personal devices that met all security requirements, such as OS and patch level and passcode, could access corporate resources. If a device was lost or stolen, IT could take action, for example blocking or wiping work apps and documents without touching the rest of the device.
On COPE devices, Android devices were separated at operating system level with the Android Enterprise work profile, giving users two clearly distinct spaces for personal and work. On iOS, separation works at app level, with managed apps and restrictions on data sharing between managed and unmanaged apps. On both platforms, a secure repository such as OneDrive or SharePoint, on premises or in the cloud, was enforced for work documents.
The enterprises ran a hybrid environment, a mix of on-site and cloud services. Most services, including email, instant messaging and storage for non-sensitive documents, were in the cloud and reachable from anywhere with an internet connection. Multi-factor authentication (MFA) strengthened the sign-in, with a prompt on a registered mobile device whenever a user accessed a sensitive resource. Today, phishing-resistant methods such as passkeys are the better choice than simple push approvals.
For privacy and security reasons, some sensitive information, such as customer data, and some services, such as in-house app development and the related intellectual property, could not move to the cloud. Reaching these resources from outside the office, whether from a home office, an airport or a customer site, is harder. A virtual private network (VPN) provided the secure end-to-end connection between employee devices and the internal network, and most employees already knew how to use it. How a Zero Trust approach can extend this is covered in part three.
The mobile fleet was managed with a UEM solution, which any business running a digital workplace needs to keep its assets under control. A UEM deploys apps, provides access to corporate resources, enforces security policies and takes action when a device is at risk or non-compliant. A monitoring solution gave a real-time overview of the health of all assets, detected potential issues and helped forecast capacity needs, such as upgrading endpoints or back-end infrastructure.
With more people working from home, cyberattacks increased, so the focus shifted to protecting all endpoints and the business-critical data on them with next-generation antivirus based on behavior-based security. Today this is typically part of endpoint detection and response (EDR), explained in EPP, EDR and MTD.
Both offices had their own local IT teams, so ownership was defined to avoid silos, where divisions, offices, regions or countries operate independently and do not share information. In very specific cases that can be justified, but in general it is inefficient: it leads to as many IT infrastructures as there are silos, which means higher total cost of ownership, a poorer user experience, more complex daily administration and a weaker response to security challenges. A unified strategy that combines assets wherever possible, while respecting genuine local requirements, is the better choice.
A digital workplace strategy is only as good as its adoption, and that requires understanding and commitment, which come through training. Employees need to understand the security concerns and their own responsibility when handling sensitive customer and business data. Balancing security and usability is what makes the strategy succeed. Part three, X-ray of a Successful Global Enterprise Digital Workplace Strategy, adds data residency, compliance and Zero Trust across countries.
It covers device ownership models, access to on-premises and cloud data, protection of devices and data, endpoint management and monitoring, clear responsibilities across IT, security and mobility teams, and training for employees.
Often both. COPE suits employees who need mobile access to sensitive data, because IT can enforce stronger controls. BYOD with app containerization suits employees for whom mobile access is useful but not essential.
For resources that stay on premises, remote access needs a secure connection, and a VPN is a common way to provide it. Zero Trust Network Access (ZTNA) is an alternative that grants access per application based on identity and device state.
Separate infrastructures for each office raise total cost of ownership, make daily administration more complex and weaken the response to security incidents. A unified strategy with clearly defined ownership keeps one standard while leaving room for local requirements.
Planning or reworking your enterprise digital workplace? Our team supports endpoint management and endpoint security across the major platforms, and ISEC7 SPHERE monitors your digital workplace infrastructure in one console. Contact us with any questions.