this post was submitted on 06 Feb 2025
16 points (100.0% liked)

Privacy

6 readers
8 users here now

Everything about privacy (the confidentiality pillar of security) -- but not restricted to infosec. Offline privacy is also relevant here.

founded 1 year ago
MODERATORS
 

Just a reminder, especially in this wild time we live in. DO NOT INSTALL WORK MDM ON YOUR PERSONAL DEVICE.
If your work requires Microsoft Intune or similar MDM, to get email/teams/slack. don't accept it. It opens your device up for them to access private data and disable/delete your phone (even if they say they wont, they can)

https://blog.cdemi.io/never-accept-an-mdm-policy-on-your-personal-phone/

#privacy #android #iphone #work #email #outlook #microsoft

you are viewing a single comment's thread
view the rest of the comments
[–] matmair@mastodon.social 1 points 4 weeks ago (1 children)

@notsle@kzoo.to this article is either clickbait or the author has several year old experience. Most of the described things are only available on fully supervised devices. To get one of those you need to wipe the device and get permanent warnings in the lockscreen.
There are dangers but they are clearly communicated by the OS.

[–] notsle@kzoo.to 1 points 4 weeks ago* (last edited 4 weeks ago) (1 children)

@matmair and most companies do not have the time/experience to do set it up properly.

Microsoft intune shows these warnings when going through the steps.

Even if Intune restricts what my work can do in their app. Microsoft is still requesting a lot of permissions.

Even the simple fact that they can wipe my phone is enough to not sign into outlook with iOS.

[–] matmair@mastodon.social 1 points 4 weeks ago (1 children)

@notsle@kzoo.to this is completely controllable by the company. Maybe you just have a shitty IT department and shouldn’t work somewhere that does not educate their IT staff appropriately?

We have intune at work - we do not request the option to wipe personal devices. Flaming a net-good technology because you have had bad experience is not a good look.

[–] notsle@kzoo.to 1 points 4 weeks ago* (last edited 4 weeks ago)

@matmair so send me a screenshot of what your mdm profile looks like on your device and what the permissions that it gives.

What net-good is there for individuals to allow any control over their device to their employer?

You even said the best part. “Controllable by the company” I choose to give zero control of my personal device or its contents to “the company“