I work for a company that provided me with a laptop, and I've been assigned to a banking client for almost two years. The client environment uses a layered setup: Azure Virtual Desktop, then a remote server, and finally the actual work machine. For about a year, I accessed this environment from my personal MacBook instead of the approved company laptop because I preferred using it.
I didn't intentionally download or transfer anything. The remote machine blocks copying and pasting as well as downloading files to the local computer. However, the client discovered that I was using an unapproved personal device, and an internal report is now being prepared. I'm worried this could lead to termination. How serious is the situation likely to be?
5 Answers
The exact consequences depend on the written policies, your contract, and the country you’re in. Check whether personal-device access was explicitly prohibited or whether it was simply not approved. If the system allowed access from your laptop, that may indicate a gap in conditional-access or device-compliance controls, but it doesn’t automatically excuse bypassing the approved process. Document the facts accurately and avoid deleting or changing anything.
Start preparing practically, but don’t panic or speculate with coworkers. Use the approved laptop from now on, follow any instructions from security or HR, and get independent employment advice if you’re asked to sign a statement or disciplinary document. Keep your explanation factual rather than arguing that the system should have prevented you from connecting.
The fact that the remote environment blocked copy/paste and file transfers is relevant, but it doesn’t prove there was no security risk. Your personal laptop could still have created concerns around authentication, malware, logging, screenshots, local caching, or regulatory compliance. Explain what device you used, when you used it, what systems you accessed, and confirm that you did not download or transfer files.
For banking and other regulated industries, unauthorized-device access is generally treated more seriously than it would be at an ordinary company. At the same time, termination is not guaranteed. The investigation may consider whether the device was managed, whether any data left the environment, how long this went on, whether you were trained on the rule, and whether technical controls should have blocked access.
This could be taken very seriously, especially because the client is a bank. Company and client laptops are usually required for security, monitoring, compliance, and incident-response reasons. Even if you didn’t move any files, using an unapproved device may violate policy. Be honest, cooperate with the investigation, and review the applicable company and client policies before making assumptions about the outcome.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures