October 1, 2026

What Happens When an Employee Loses a Company Laptop or Phone?

Losing a company laptop, phone or tablet can happen surprisingly easily.

A laptop might be left on a train. A phone could disappear from a hotel. A tablet might be stolen from a vehicle.

For the employee, the immediate concern is usually replacing the device. For the business, however, the bigger question should be:

What company information could somebody access from it?

This is where having properly managed business devices can make a significant difference.

When devices are managed, encrypted and connected to systems such as Microsoft Intune and Microsoft Entra ID, losing the physical device does not necessarily mean losing control of your company data.

The importance of reporting a lost device quickly

One of the most important things an employee can do when a company device goes missing is report it immediately.

It can be tempting to spend time searching for a misplaced laptop or wait until the following morning before contacting IT. However, the sooner your IT provider knows about the incident, the sooner they can begin protecting the business.

A good lost device procedure should be straightforward.

The employee should contact their IT helpdesk or MSP, explain which device has been lost and where and when it was last seen. They should also confirm whether they believe the device was lost or stolen and whether there is any possibility that passwords, PINs or other login information could have been exposed.

If the device has been stolen, the incident should also be reported to the police where appropriate.

The IT team can then begin securing the device and the accounts connected to it.

What happens when an MSP is notified?

A lost company device should be treated as a security incident, rather than simply a request for a replacement laptop.

A properly managed IT environment should already contain information about the device, including its assigned employee, operating system, encryption status, Microsoft Intune status, Microsoft Entra registration and security compliance.

This information allows the IT team to understand exactly what has been lost and what access may need to be restricted.

The next steps will depend on the device, how it has been configured and what information the employee was able to access.

Protecting access to Microsoft 365

If the lost device is registered with Microsoft Entra ID, an administrator can disable the device where appropriate.

This can help prevent the device from continuing to access company resources such as Microsoft 365, SharePoint, Teams, OneDrive and other cloud applications protected by Microsoft identity controls.

This becomes particularly valuable when combined with Conditional Access policies, which can require devices to meet specific security and compliance requirements before accessing company information.

If there is also concern that the employee's password or login credentials may have been compromised, the IT team may need to take additional steps.

These can include revoking active sessions, resetting passwords, reviewing multi factor authentication methods, checking recent sign ins and investigating any unusual activity.

The objective is to protect both the physical device and the employee's user account.

How Microsoft Intune can help

Microsoft Intune gives IT administrators a range of management options for supported devices.

Depending on the device and its configuration, these can include remote locking, retiring or wiping the device, locating it where supported and carrying out other security actions.

The appropriate response will depend on the circumstances.

If an employee believes they have simply misplaced a device and expects to find it again, a remote lock may be appropriate.

If a personally owned device contains company information, retiring the organisational data may be more suitable.

If a company owned laptop has been stolen and is unlikely to be recovered, a remote wipe may be considered.

The important point is that these actions should form part of a documented incident response process rather than being decided from scratch every time something goes missing.

What if the laptop is switched off?

There is an important limitation to remote management.

Remote commands cannot normally be carried out immediately if a lost laptop has no internet connection. The device needs to reconnect before it can receive the relevant instruction.

This is why remote wiping should never be viewed as the only protection a business has.

Security needs to be in place before the device disappears.

Why BitLocker matters

One of the key protections for a managed Windows laptop is full disk encryption such as BitLocker.

BitLocker encrypts the information stored on the laptop's drive. This means that if an unencrypted laptop is stolen, there may be additional ways for someone to attempt to access the information stored on it.

With managed devices, an MSP can monitor whether encryption is enabled and whether devices are meeting the company's security requirements.

That means a business should not have to wait until a laptop goes missing to discover that encryption was never enabled.

Good security should happen before something goes wrong

This is one of the biggest differences between proactive managed IT and reactive IT support.

Reactive IT often discovers problems after an incident has already happened.

Managed IT should be identifying potential problems beforehand.

Your IT provider should already have visibility of which devices are encrypted, which are compliant, which have outdated operating systems, which users have administrator privileges and which devices have access to company information.

If a laptop disappears and the business only then discovers that important security controls were missing, the situation becomes considerably more difficult.

What about employees using their own phones?

Many businesses now allow employees to access work emails, Teams and company documents from their personal phones.

This creates another challenge.

A business may want to protect its information without having the ability or desire to wipe an employee's entire personal phone.

Microsoft Intune can support app protection policies that help protect company information within supported applications. Depending on the configuration, these controls can require authentication, restrict certain types of data transfer and allow organisational data to be removed without necessarily deleting the employee's personal information.

This can be particularly useful if an employee leaves the company or loses their personal phone.

The aim is to protect the business without unnecessarily interfering with the employee's personal data.

What about UK GDPR?

A lost company device can potentially become a personal data breach if it contains personal information.

The incident should therefore be assessed carefully.

Not every lost device automatically needs to be reported to the ICO. The business needs to consider what information was stored on the device, whether it was encrypted, whether access has been contained and what risk there may be to the individuals whose information was involved.

An MSP can provide important technical information during this assessment, including whether the device was encrypted, whether remote actions were issued and whether the associated account was successfully disabled.

The business remains responsible for its data protection obligations and should seek appropriate compliance or legal advice where required.

Preparing your devices before they leave the office

The best time to think about a lost laptop is before it is lost.

A strong managed device setup can include Microsoft Intune enrolment, Microsoft Entra registration, BitLocker encryption, secure authentication, multi factor authentication, endpoint security, Conditional Access policies, automatic updates and device compliance monitoring.

Businesses should also have a clear and tested lost device procedure.

The objective is simple.

Assume that one of your company devices will eventually be lost and build your security around that possibility.

How 39D can help

At 39D, we provide managed IT support and Microsoft 365 management for growing businesses.

As part of a managed device strategy, we can help businesses deploy and manage technologies including Microsoft Intune, Microsoft Entra, BitLocker, endpoint security and Microsoft 365 access controls.

That means that when an employee loses a company laptop, the response does not begin with questions about what was installed on the device.

Instead, the device can already be documented, encrypted and managed.

Your IT team can identify the device, restrict access, protect company information and help the employee get back to work.

If you are unsure whether your current laptops, phones and tablets are properly managed or secured against loss or theft, speak to 39D about a Managed Device and Microsoft 365 Security Review.

A lost device does not have to become a major security incident. The right preparation and managed IT controls can help your business respond quickly and protect the information that matters.

‍