← Resources

Guest Wi-Fi & BYOD Expectations

How guest Wi-Fi is isolated from your business systems, and what to expect when personal devices are used for work.

Created September 7, 2026

Guest Wi-Fi & BYOD Expectations

Two everyday questions come up often enough to spell out clearly: what happens when a visitor asks for Wi-Fi, and what's expected when someone uses a personal device for work.

Guest Wi-Fi Is Quarantined, On Purpose

Guest Wi-Fi runs on its own network, completely separated from the systems your business actually depends on. A device connected to guest Wi-Fi cannot see or reach your file shares, printers, servers, or any other internal endpoint, it gets internet access and nothing else. This runs on the same business-grade equipment covered in Our Networking Standards, configured specifically to keep that separation in place.

This isn't a formality, an unmanaged visitor's device is exactly the kind of thing that shouldn't have a path to your internal network, whether that visitor is a client, a contractor, or someone's guest waiting in the lobby.

The guest network is open, no password needed, so anyone (a client, a contractor, someone waiting in the lobby) can connect on their own without you having to do anything. Just don't share your main Wi-Fi credentials with a visitor, point them to the guest network instead.

Using a Personal Device for Work

Checking email or Teams from a personal phone happens, and it's fine, with a few expectations:

  • MFA still applies. Whatever device you're on, multi-factor authentication is enforced the same way.
  • Don't store sensitive company files locally on a personal device. Work through the apps directly (Outlook, Teams, OneDrive) rather than downloading things onto a device we don't manage.
  • A personal device isn't covered the way a company-managed one is. It's not enrolled in patching, Huntress, or the rest of the managed stack, so our support is limited to the company accounts and data on it, not the device itself.

What You Should Do

  • Point visitors to the open guest network rather than handing out your main network's password, no need to loop us in for a one-off visitor.
  • If a personal device with access to company email or files is lost or stolen, report it immediately, we can revoke that device's access to company systems right away, even though we don't manage the device itself.
  • If your team is doing a meaningful amount of work from personal devices, it's worth a conversation about whether some of them should be brought under full management instead.

Need Help?

If you run into any issues, reach out to the Triumphant support team: