▲ 1973 ▼ Not allowed to work from home (sh.itjust.works) submitted 2 years ago by sjmarf@sh.itjust.works to c/maliciouscompliance@lemmy.world 224 comments fedilink hide all child comments
[–] TexasDrunk@lemmy.world 23 points 2 years ago (2 children) I really don't mind these days as long as they have a MDM so I can have it on a separate profile, but without that I'm totally with you. permalink fedilink source parent hideshow 4 child comments replies: [–] 200ok@lemmy.world 10 points 2 years ago (1 child) What's MDM? permalink fedilink source parent hideshow 2 child comments replies: [–] Knoxvomica@lemmy.ca 15 points 2 years ago (2 children) Mobile device management. Basically software to manage mobile devices owned by a company. permalink fedilink source parent hideshow 4 child comments replies: [–] TexasDrunk@lemmy.world 7 points 2 years ago (1 child) Or work profiles on BYODs permalink fedilink source parent hideshow 2 child comments replies: [–] 200ok@lemmy.world 3 points 2 years ago Thank you permalink fedilink source parent [–] 200ok@lemmy.world 2 points 2 years ago Thank you permalink fedilink source parent [–] Rekorse@sh.itjust.works 4 points 2 years ago (1 child) How does the separate profile keep the company from factory resetting the whole device? permalink fedilink source parent hideshow 2 child comments replies: [–] TexasDrunk@lemmy.world 12 points 2 years ago* (1 child) Because they can only see, install, or wipe things inside the work profile. It's all sandboxed. Quick edit: This is for Android. I have no idea about iPhones. permalink fedilink source parent hideshow 2 child comments replies: [–] Rekorse@sh.itjust.works 4 points 2 years ago (2 children) I don't believe iPhone allows this, or at least the customers at my work don't enable it for iOS. I hadn't had to set it up myself though so I wasnt sure. I would rather avoid the MDM altogether if possible. permalink fedilink source parent hideshow 4 child comments replies: [–] TexasDrunk@lemmy.world 3 points 2 years ago I get it, and I don't blame anyone for that choice. I made mine based on utility, convenience, and knowledge of the tool for me. I don't care how convenient it makes things for work. They'll give me a phone if it's that convenient for them. But I'm not qualified to make that decision for anyone else. permalink fedilink source parent [–] TexasDrunk@lemmy.world 1 point 2 years ago (1 child) I shot a message to a colleague who is still in IT (I'm into other shit these days) and he says you're correct. IOS doesn't allow for this. The IT department running Mobile Device Management would have to set up Mobile App Management (MAM) on their side. So it's possible that they only get access to those apps without giving them access to the whole device but a lot of lazy departments won't do it. permalink fedilink source parent hideshow 2 child comments replies: [–] Rekorse@sh.itjust.works 1 point 2 years ago Well that explains why one of the other teams clients revolted against intune and switched to just using MFA for o365. Its funny, they are so jaded by the MDM they keep grilling people about the MFA and if it gives access to their phones, etc. I also think some people are starting to catch on to Microsoft's apps collecting too much data, including MFA. Theres a big banner when you first set it up asking for permission. permalink fedilink source parent
[–] 200ok@lemmy.world 10 points 2 years ago (1 child) What's MDM? permalink fedilink source parent hideshow 2 child comments replies: [–] Knoxvomica@lemmy.ca 15 points 2 years ago (2 children) Mobile device management. Basically software to manage mobile devices owned by a company. permalink fedilink source parent hideshow 4 child comments replies: [–] TexasDrunk@lemmy.world 7 points 2 years ago (1 child) Or work profiles on BYODs permalink fedilink source parent hideshow 2 child comments replies: [–] 200ok@lemmy.world 3 points 2 years ago Thank you permalink fedilink source parent [–] 200ok@lemmy.world 2 points 2 years ago Thank you permalink fedilink source parent
[–] Knoxvomica@lemmy.ca 15 points 2 years ago (2 children) Mobile device management. Basically software to manage mobile devices owned by a company. permalink fedilink source parent hideshow 4 child comments replies: [–] TexasDrunk@lemmy.world 7 points 2 years ago (1 child) Or work profiles on BYODs permalink fedilink source parent hideshow 2 child comments replies: [–] 200ok@lemmy.world 3 points 2 years ago Thank you permalink fedilink source parent [–] 200ok@lemmy.world 2 points 2 years ago Thank you permalink fedilink source parent
[–] TexasDrunk@lemmy.world 7 points 2 years ago (1 child) Or work profiles on BYODs permalink fedilink source parent hideshow 2 child comments replies: [–] 200ok@lemmy.world 3 points 2 years ago Thank you permalink fedilink source parent
[–] Rekorse@sh.itjust.works 4 points 2 years ago (1 child) How does the separate profile keep the company from factory resetting the whole device? permalink fedilink source parent hideshow 2 child comments replies: [–] TexasDrunk@lemmy.world 12 points 2 years ago* (1 child) Because they can only see, install, or wipe things inside the work profile. It's all sandboxed. Quick edit: This is for Android. I have no idea about iPhones. permalink fedilink source parent hideshow 2 child comments replies: [–] Rekorse@sh.itjust.works 4 points 2 years ago (2 children) I don't believe iPhone allows this, or at least the customers at my work don't enable it for iOS. I hadn't had to set it up myself though so I wasnt sure. I would rather avoid the MDM altogether if possible. permalink fedilink source parent hideshow 4 child comments replies: [–] TexasDrunk@lemmy.world 3 points 2 years ago I get it, and I don't blame anyone for that choice. I made mine based on utility, convenience, and knowledge of the tool for me. I don't care how convenient it makes things for work. They'll give me a phone if it's that convenient for them. But I'm not qualified to make that decision for anyone else. permalink fedilink source parent [–] TexasDrunk@lemmy.world 1 point 2 years ago (1 child) I shot a message to a colleague who is still in IT (I'm into other shit these days) and he says you're correct. IOS doesn't allow for this. The IT department running Mobile Device Management would have to set up Mobile App Management (MAM) on their side. So it's possible that they only get access to those apps without giving them access to the whole device but a lot of lazy departments won't do it. permalink fedilink source parent hideshow 2 child comments replies: [–] Rekorse@sh.itjust.works 1 point 2 years ago Well that explains why one of the other teams clients revolted against intune and switched to just using MFA for o365. Its funny, they are so jaded by the MDM they keep grilling people about the MFA and if it gives access to their phones, etc. I also think some people are starting to catch on to Microsoft's apps collecting too much data, including MFA. Theres a big banner when you first set it up asking for permission. permalink fedilink source parent
[–] TexasDrunk@lemmy.world 12 points 2 years ago* (1 child) Because they can only see, install, or wipe things inside the work profile. It's all sandboxed. Quick edit: This is for Android. I have no idea about iPhones. permalink fedilink source parent hideshow 2 child comments replies: [–] Rekorse@sh.itjust.works 4 points 2 years ago (2 children) I don't believe iPhone allows this, or at least the customers at my work don't enable it for iOS. I hadn't had to set it up myself though so I wasnt sure. I would rather avoid the MDM altogether if possible. permalink fedilink source parent hideshow 4 child comments replies: [–] TexasDrunk@lemmy.world 3 points 2 years ago I get it, and I don't blame anyone for that choice. I made mine based on utility, convenience, and knowledge of the tool for me. I don't care how convenient it makes things for work. They'll give me a phone if it's that convenient for them. But I'm not qualified to make that decision for anyone else. permalink fedilink source parent [–] TexasDrunk@lemmy.world 1 point 2 years ago (1 child) I shot a message to a colleague who is still in IT (I'm into other shit these days) and he says you're correct. IOS doesn't allow for this. The IT department running Mobile Device Management would have to set up Mobile App Management (MAM) on their side. So it's possible that they only get access to those apps without giving them access to the whole device but a lot of lazy departments won't do it. permalink fedilink source parent hideshow 2 child comments replies: [–] Rekorse@sh.itjust.works 1 point 2 years ago Well that explains why one of the other teams clients revolted against intune and switched to just using MFA for o365. Its funny, they are so jaded by the MDM they keep grilling people about the MFA and if it gives access to their phones, etc. I also think some people are starting to catch on to Microsoft's apps collecting too much data, including MFA. Theres a big banner when you first set it up asking for permission. permalink fedilink source parent
[–] Rekorse@sh.itjust.works 4 points 2 years ago (2 children) I don't believe iPhone allows this, or at least the customers at my work don't enable it for iOS. I hadn't had to set it up myself though so I wasnt sure. I would rather avoid the MDM altogether if possible. permalink fedilink source parent hideshow 4 child comments replies: [–] TexasDrunk@lemmy.world 3 points 2 years ago I get it, and I don't blame anyone for that choice. I made mine based on utility, convenience, and knowledge of the tool for me. I don't care how convenient it makes things for work. They'll give me a phone if it's that convenient for them. But I'm not qualified to make that decision for anyone else. permalink fedilink source parent [–] TexasDrunk@lemmy.world 1 point 2 years ago (1 child) I shot a message to a colleague who is still in IT (I'm into other shit these days) and he says you're correct. IOS doesn't allow for this. The IT department running Mobile Device Management would have to set up Mobile App Management (MAM) on their side. So it's possible that they only get access to those apps without giving them access to the whole device but a lot of lazy departments won't do it. permalink fedilink source parent hideshow 2 child comments replies: [–] Rekorse@sh.itjust.works 1 point 2 years ago Well that explains why one of the other teams clients revolted against intune and switched to just using MFA for o365. Its funny, they are so jaded by the MDM they keep grilling people about the MFA and if it gives access to their phones, etc. I also think some people are starting to catch on to Microsoft's apps collecting too much data, including MFA. Theres a big banner when you first set it up asking for permission. permalink fedilink source parent
[–] TexasDrunk@lemmy.world 3 points 2 years ago I get it, and I don't blame anyone for that choice. I made mine based on utility, convenience, and knowledge of the tool for me. I don't care how convenient it makes things for work. They'll give me a phone if it's that convenient for them. But I'm not qualified to make that decision for anyone else. permalink fedilink source parent
[–] TexasDrunk@lemmy.world 1 point 2 years ago (1 child) I shot a message to a colleague who is still in IT (I'm into other shit these days) and he says you're correct. IOS doesn't allow for this. The IT department running Mobile Device Management would have to set up Mobile App Management (MAM) on their side. So it's possible that they only get access to those apps without giving them access to the whole device but a lot of lazy departments won't do it. permalink fedilink source parent hideshow 2 child comments replies: [–] Rekorse@sh.itjust.works 1 point 2 years ago Well that explains why one of the other teams clients revolted against intune and switched to just using MFA for o365. Its funny, they are so jaded by the MDM they keep grilling people about the MFA and if it gives access to their phones, etc. I also think some people are starting to catch on to Microsoft's apps collecting too much data, including MFA. Theres a big banner when you first set it up asking for permission. permalink fedilink source parent
[–] Rekorse@sh.itjust.works 1 point 2 years ago Well that explains why one of the other teams clients revolted against intune and switched to just using MFA for o365. Its funny, they are so jaded by the MDM they keep grilling people about the MFA and if it gives access to their phones, etc. I also think some people are starting to catch on to Microsoft's apps collecting too much data, including MFA. Theres a big banner when you first set it up asking for permission. permalink fedilink source parent