Connecting your own laptop to work Wi-Fi does not enrol it in your employer's device management. Enrolment is a separate, deliberate step, installing a profile or signing into a work account, and joining a network never does that on its own. Many workplaces also route personal devices onto a separate guest network with its own logging.
What actually happens when a laptop joins work Wi-Fi
Associating with a wireless network is a network level handshake. The laptop exchanges credentials with an access point, gets assigned an address, and starts routing traffic through that network's equipment. None of that process installs anything on the laptop, changes an operating system setting, or places the device under an administrator's control. It is the same exchange that happens when the same laptop joins a coffee shop's network, only the equipment on the other end belongs to the employer instead of the cafe.
People often assume that because the network belongs to the company, the device touching it must now answer to the company too. That assumption skips a real distinction. A network connection and a management enrolment are two different systems, built by different software, and one does not imply the other.
Enrolment is a separate, deliberate step
A device becomes managed through mobile device management, sometimes called MDM, and that only happens when something is deliberately installed or signed into. Two things typically do it: installing a configuration profile the organisation provides, or signing into a work account inside an operating system setting built specifically to hand control to that account's administrator. Both are actions a person takes on purpose, and both are visible while they happen, usually through a prompt asking for confirmation before anything is applied.
Joining a Wi-Fi network triggers neither of those. anything a managed or employer-administered device can see is the accurate boundary here: an unmanaged personal laptop that has never been through that profile installation or that account sign in stays outside what an administrator can see or change on the device itself, network connection or not. The Wi-Fi password gets you onto the network. It does not get the organisation onto your laptop.
Where organisations commonly put personal devices instead
Rather than trying to enrol every personal device that connects, many workplaces solve this with a second network entirely. A segmented guest network, sometimes labelled that plainly in the Wi-Fi list and sometimes given a separate name, carries traffic from personal and visitor devices on infrastructure kept apart from the one issued laptops use. Logging on that segmented network is frequently lighter than on the corporate one, and in some setups it is configured differently enough that it does not tie back to an employee identity at all, only to a device on the guest segment.
This is worth checking directly rather than assuming either way. Which network a personal laptop actually lands on, the main corporate one or a separate guest segment, is usually visible in the Wi-Fi network name itself, and it is a fair question to ask an IT contact directly if it is not obvious.
What the network layer still sees, and where that is covered
None of the above removes network level visibility entirely. Whichever network a laptop joins, personal or managed, guest or corporate, the equipment carrying that traffic is still in a position to see which domains a device connects to. The mechanism behind that, DNS lookups and the TLS handshake, is covered in full in what an IT department can see over HTTPS, and it applies the same way regardless of who owns the laptop making the connection.
What a VPN changes in this exact situation
A VPN is the tool built to address that network level visibility, and the scenario of a personal device on a work network is exactly the case where it does the most. That comparison, including where a VPN stops helping once a device is actually enrolled and managed, is worked through in does a VPN hide ChatGPT usage from a work network. An unenrolled personal laptop is the situation where a VPN has the most room to work, since there is no device level software for it to sit alongside.
Two separate questions, two separate answers
Whether a device is enrolled in management and what the network can see about its connections are different layers with different mechanisms. Confusing the two leads to either more worry than the situation warrants or less caution than it deserves, depending on which layer actually applies.
Where Docognito fits, and where it does not
the visible page, redrawn as a document editor, the browser tab title and the tab icon are what Docognito changes, and none of that reaches either layer this article covers. It does not read, alter or check whether a laptop is enrolled in device management, and it has no access to Wi-Fi network settings or routing. A personal laptop that has never been enrolled runs the extension exactly the same way a managed one would, because the extension operates entirely inside a browser tab, well above both the enrolment question and the network question.
Does joining work Wi-Fi enroll your personal laptop?
Joining work Wi-Fi with a personal laptop does not, on its own, place that laptop under an employer's device management. Enrolment requires a separate, visible step that connecting to a network never performs on its own, and many organisations route personal devices onto a guest network with lighter logging besides. What the network itself can still observe about a connection is a different layer, worked through in the two linked articles above, and it applies whether or not a device was ever enrolled at all.