<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

Why Ownership Model Matters: BYOD, COBO and COPE

Reviewed and updated in October 2026.

Choosing an ownership model for your mobile devices is rarely as simple as picking BYOD because it is cheap or COBO because you work in a regulated industry. Most organizations need a more flexible, hybrid model that meets their security requirements and the needs of employees, many of whom already carry a smartphone all day.

An ownership model defines who owns a mobile device, who pays for it and how much control the organization has over it. The three common models are BYOD, where employees use their own devices and only work data is managed; COBO, where the company owns and fully controls devices used for business only; and COPE, where the company owns and manages the device but leaves room for personal use. Many organizations combine them by user group.

Why device ownership became complicated

Over the past decade, smartphones and laptops have changed how we use devices. Employees with corporate devices also use them for private things, and employees with personal devices use them for work.

The first scenario is as old as company-issued devices. People have always wanted their work device to make life easier too, from family reaching them by pager to Nextel push-to-talk among friends and family in the US. Today they want to check private email, read the news and use social media or games on the same device instead of carrying a second one.

The second scenario came later, once everyone owned at least one device. Some companies saw a chance to be flexible and let employees use their personal devices at work with only minor changes to the corporate infrastructure.

Here is how the options compare.

BYOD: Bring Your Own Device

With BYOD, employees use their own mobile device for work tasks such as email and business apps, without compromising security.

IT has little or no control over the device itself, so we recommend a containerized solution that keeps corporate data secure at rest and in transit, regardless of the device's security posture. On Android this is the work profile; on iPhone and iPad, Apple's User Enrollment keeps managed work data separate from personal data. BYOD saves the cost of buying devices, but it has its own limits:

  • Device variety: the service desk has to support a practically unlimited range of devices, and enterprise apps can run into compatibility issues.
  • Loss, damage or theft: the employee may not be able to buy the same model again, and the replacement may not meet your security requirements.
  • Costs for the employee: many people do not want to make work calls from their private number or spend their own data allowance on work traffic they pay for themselves.

COBO: Corporate Owned, Business Only

COBO is used where full control over device and data is required and there is little or no room for private use, typically in regulated environments such as federal administration and government. It is one of the easiest models to manage, because only a curated set of approved devices runs a defined set of vetted enterprise apps.

COBO is the most secure option, which is why it suits regulated environments. The downside is user acceptance. Users cannot install personal apps or keep personal data such as photos, and few want to carry two phones, so many leave the work device at the office after hours. Where COBO is chosen, that is usually acceptable, because the device is simply another tool in the employee's toolbox.

COPE: Corporate Owned, Personally Enabled

With COPE, the device belongs to the company and is managed by it, but the user gets a separate, walled-off area for private apps and data. It balances BYOD and COBO without compromising corporate data security. On Android, the work profile on company-owned devices provides this separation, as Google explains in its overview of Android Enterprise management. We describe the management modes in Android 12 for Enterprise, and the differences between platforms in Demystifying Apple, Android Enterprise and Samsung Knox.

The same balance applies to calls and data. With dual SIM or eSIM, employees can add their private subscription to the company phone, so private calls run on their own line and work calls on the corporate one.

Device as a service and curated device lists

Some organizations reduce the effort of ownership with a device-as-a-service model, in which a provider takes over procurement, staging, replacement and collection of devices. Combined with a curated list of approved models that employees can choose from, often called CYOD (choose your own device), this gives users some choice while IT keeps the device fleet consistent. Bundling purchases can also strengthen your position when negotiating with suppliers.

How to choose the right ownership model

Choose the model or models that suit your organization, considering cost, auditability, security, management effort and the UEM platform you already run, since features differ slightly between platforms. In practice, many organizations mix models by role, as our enterprise digital workplace strategy example shows with COPE for users who handle sensitive data on the go and BYOD for everyone else.

Frequently asked questions

What is the difference between BYOD, COPE and COBO?

With BYOD the employee owns the device and the company manages only work apps and data. With COPE the company owns and manages the device but allows personal use in a separated area. With COBO the company owns and fully controls the device, and personal use is not intended.

Which ownership model is the most secure?

COBO gives the organization the most control, because only approved devices and vetted apps are allowed. That is why it is common in government and other regulated environments. COPE comes close while leaving room for personal use, and BYOD relies on containerization to protect work data.

Can an organization use several ownership models at once?

Yes, and most do. A common pattern is COPE for employees who need mobile access to sensitive data, BYOD for those who only benefit from occasional access, and COBO for devices with a single business purpose. The UEM then applies different policies per group.

How are work and personal data separated on a BYOD device?

Through containerization: on Android, a work profile keeps work apps and data apart from personal ones, and on iPhone and iPad, User Enrollment does the same for managed work data. The company can wipe work data without touching personal content.

Want help choosing or reworking your ownership model? Our team supports endpoint management across the major UEM platforms, and with ISEC7 DEVICE AS A SERVICE we take care of procurement, staging, replacement and logistics. Contact us with any questions.