Disabling a departing employee's account doesn't clear the email and contacts already on their personal phone. The setting that does is likely in your subscription.
An employee resigns on a Friday. By Monday you've disabled their Microsoft 365 account and collected the laptop. In their jacket pocket is a personal iPhone with Outlook on it — and if Outlook was set to sync contacts, every client name and mobile number from your company directory is sitting in that phone's own address book, filed next to their dentist.
You can't ask for the phone. It's theirs.
Disabling the account isn't the same as clearing the phone
Cutting off the account stops new mail from arriving. It doesn't reach backward and tidy up what's already there.
Microsoft treats this as a separate job entirely. Its own guidance on removing company data opens with the exact scenario: when a device is lost or an employee leaves, "you want to make sure company app data is removed from the device" — but "you might not want to remove personal data on the device, especially if the device is an employee-owned device."
Two different actions. Most small businesses only ever take the first one.
The fix is probably already in what you pay for
Microsoft 365 Business Premium includes Microsoft Intune Plan 1. Intune does two very different things, and the difference between them is the whole point:
- Managing the device. The company controls the phone and can wipe all of it. Right for a company-bought phone. Wrong — and usually unwelcome — for someone's personal one.
- Managing the apps on the device. In Microsoft's words, "the user controls the device, but the organization controls access to company data on the device."
The second one is done with something called an app protection policy. It works without the employee enrolling their phone in anything; Microsoft's documentation describes it as usable "independent of any mobile-device management solution." Nobody hands over their phone, and nobody signs anything.
What actually changes for the employee
Less than owners expect, which is why this is worth asking for.
The policy applies only in a work context. Intune labels data as company or personal based on where it came from — a document someone starts on their own is personal, and stays untouched. Day to day, the visible difference is a PIN when they open work email, and not being able to paste a client list out of Outlook into their personal notes app.
What you gain: on the day someone leaves, you issue a selective wipe from the Intune admin center, and company data disappears from those apps. Photos, texts, personal email, the apps themselves — all stay. Microsoft notes the wipe happens the next time the person opens the app, and can take up to 30 minutes. Contacts that Outlook synced into the phone's own address book are removed too.
What to ask for this week
Send your IT provider one sentence: "Set up Intune app protection policies for personal phones." Name it that way and they'll know exactly what you mean.
Microsoft publishes starter settings for this in its Business Premium guidance — target Core Microsoft Apps (which includes Outlook), block backing up company data to iCloud or iTunes, only let company data move to other policy-managed apps, and block saving copies anywhere except OneDrive and SharePoint. You need two policies: one for iPhone, one for Android.
Two things to know before you ask:
- Everyone covered needs an Intune license. Business Premium includes one. On other plans, check first.
- Android phones need the Company Portal app installed and the phone registered with Microsoft Entra ID. iPhones don't.
Then add one line to your offboarding routine, right under disable the account: issue a selective wipe. It takes about a minute and it's the only step that reaches the device you'll never get back. Everything else in that routine is worth a read too — the twenty-minute version is here.
Whether app protection policies are switched on is one of those settings nobody checks until the week they need it. It's also visible from inside your own tenant: a read-only scan grades a Microsoft 365 setup A–F and shows which protections are sitting there unused.
AI-researched from public sources, human-reviewed on September 10, 2026. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike finds the security gaps in your Microsoft 365 and Azure, shows how they chain into a real break-in, and hands you a plain-English fix for every one — read-only, and it never asks for permission to change anything. Start a 7-day Pro trial — no credit card.