Travelling With a Work Laptop: Whose Rules Apply

A work laptop crossing a border is not your device having a holiday. It is your employer’s equipment, under your employer’s policy, carrying your employer’s data, and usually configured with its own VPN that does not coexist happily with a personal one. Several of the choices you would make freely on a personal machine are not yours to make on this one.

Settle the questions below with your IT or security team before departure, not from a hotel room.

The device is managed, and management assumes a home network

Corporate devices typically enforce configuration through a management system: disk encryption, patching, permitted software, certificate trust, and often a mandatory VPN profile. Much of this was designed assuming the machine sits on a corporate or home network.

Abroad, three friction points appear predictably. Management check-ins may fail on restricted networks. Large policy or patch downloads may be unwelcome on a metered connection. And an always-on corporate tunnel behaves exactly like the captive-portal problem described in why hotel and airport Wi-Fi breaks your VPN, because it blocks traffic before you can sign in to the network.

Ask specifically how to get onto a captive portal on your managed device, and whether you are permitted to disable the tunnel temporarily to do so.

Do not stack a personal VPN on the corporate one

Running two tunnels at once is the most common self-inflicted failure. Routing conflicts, split-tunnel rules that no longer make sense, DNS resolution going to the wrong resolver, and management traffic taking an unexpected path all follow. Some corporate clients simply refuse to run alongside another.

Decide which one you are using and use only that:

  • For work, use the corporate tunnel. It is what your access control, logging, and internal routing expect.
  • For personal browsing on a work device, follow your employer’s policy — which may be “do not”.
  • Never assume a personal VPN improves your security posture on a managed machine. It may break the controls your employer relies on, and it hides your traffic from monitoring your employer is entitled to perform.

If you also want a personal tunnel while travelling, put it on your personal device.

Questions to ask before you go

  • Is travel to this country permitted with this device? Some organisations restrict destinations for data protection, export control, or security reasons.
  • Should I take a loaner instead? Many organisations issue a minimal travel device precisely to reduce exposure.
  • What data may be on the device? Reducing local data is the single most effective precaution, for loss, theft, and inspection alike.
  • How do I reach support in a different time zone?
  • What is the procedure if the device is lost, seized, or inspected? This must be your employer’s decision, made in advance.
  • Does anything geofence to a region? Internal tools sometimes refuse foreign addresses even through the corporate tunnel.
  • Is tethering to my phone acceptable? Often preferable to a hotel network, and it interacts with your mobile plan choice in roaming vs local SIM vs eSIM.

Borders, inspection, and why this is not your call

Devices can be inspected when crossing borders, and practice differs substantially between countries and situations. On a personal device you make your own judgement about what to carry — the reasoning is in how to protect your phone data at a border crossing and can border agents search my phone.

On a work device the data is not yours, and any decision about how to respond to an inspection may carry obligations for your employer, including confidentiality duties owed to clients. That makes it a question for your legal or security team before you travel, with a documented procedure — not something to improvise at a counter. If your organisation has no such procedure, asking for one is a reasonable request.

Practical steps that always help

Reduce the payload. Sync what you need, remove what you do not, empty local caches of sensitive material.

Verify remote access from outside the office a few days before departure, on a network that is not your corporate one.

Know the alternative protocol or backup access method for the corporate client, and how to switch.

Confirm your second factor works without your usual phone number, since a SIM swap can break it — see why 2FA breaks when you travel.

Keep it physically with you. Hotel rooms and safes are not strong protection, and an unattended device is a larger risk than any network you will use.

Expect verification prompts. New country plus new network plus corporate systems means additional authentication; have your factors to hand.

Test the whole chain at home, as part of the pre-departure connectivity checklist.

When work access fails abroad

Diagnose in the same order as anything else: is the network blocking you, is the country filtering, is the service refusing your location, or is your account being challenged? The sequence is in blocked by the network or the service. Corporate tools add one extra possibility worth checking early — a geofence on the internal service itself, which no amount of reconnecting will move and which only your IT team can lift.

Bottom line

On a managed device your employer’s policy outranks your preferences, one tunnel is the maximum, and the border questions are institutional rather than personal. Get the destination, the data, the portal procedure, and the inspection procedure agreed before you pack it.