
“If the company supplies and owns the phone, then the organization owns the full operating system, but provisions an isolated Work Profile alongside a Personal Profile,” Stahie said. “Everything related to work, email clients, and any other apps runs in its own separate sandbox, and the user can’t install anything they shouldn’t in the Work Profile.”
While this is not a “perfect solution,” Stahie believes that, when paired with dedicated mobile security and employee training around suspicious applications, it can help.
Google itself allows Workspace administrators to turn Early Access applications off for their entire organization or restrict access by organizational unit or group, giving enterprises a way to limit exposure if they deem the risk too high.
