this post was submitted on 30 May 2024
210 points (94.1% liked)

Asklemmy

43963 readers
2407 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy ๐Ÿ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~

founded 5 years ago
MODERATORS
 

So my company decided to migrate office suite and email etc to Microsoft365. Whatever. But for 2FA login they decided to disable the option to choose "any authenticator" and force Microsoft Authenticator on the (private) phones of both employees and volunteers. Is there any valid reason why they would do this, like it's demonstrably safer? Or is this a battle I can pick to shield myself a little from MS?

you are viewing a single comment's thread
view the rest of the comments
[โ€“] xavier666@lemm.ee 57 points 6 months ago (2 children)

Not a good solution but a decent one. Create a work profile on your phone, using Shelter (Fdroid, open source), and put all your work apps on that. Your data and processes are isolated and you can turn off all your work apps with a single tap. It's like a secondary virtual phone.

[โ€“] jaschen@lemm.ee 7 points 6 months ago (3 children)

Wow thanks friend! Does the 2FA work in this silo?

[โ€“] Max_P@lemmy.max-p.me 17 points 6 months ago (1 children)

Just like anywhere else. All it does is sandbox work apps from personal apps so they don't talk to eachother (not even screenshots!)

[โ€“] jaschen@lemm.ee 4 points 6 months ago

This is awesome!

[โ€“] xavier666@lemm.ee 3 points 6 months ago (1 children)

As long as the work profile is on.

[โ€“] jaschen@lemm.ee 2 points 6 months ago

Thanks! I just installed it.

[โ€“] alphacyberranger@sh.itjust.works 2 points 6 months ago (1 children)

Can confirm it works. I have been doing it like this for the past 2 years.

[โ€“] jaschen@lemm.ee 1 points 6 months ago

This is awesome. Thank you my internet friend.

[โ€“] LordCrom@lemmy.world 5 points 6 months ago (2 children)

Don't mix business and personal.

Don't Install any corp app on a personal phone. No matter what.

[โ€“] Catsrules@lemmy.ml 1 points 5 months ago* (last edited 5 months ago) (1 children)

Don't mix business and personal

This method basically is creating two phone with one. Why wouldn't this be a good solution with keeping business and personal separate?

[โ€“] LordCrom@lemmy.world 4 points 5 months ago (1 children)

If information is ever subject of a subpoena, your phone could be seized as evidence.... OS separation doesn't matter. Just like you wouldn't check corporate email or keep corp documents on your personal laptop...because your laptop could be seized for any corp legal action

[โ€“] Catsrules@lemmy.ml 2 points 5 months ago* (last edited 5 months ago)

Yeah that is a fair point.

I have never been involved in anything like that, so I don't know how big of a risk that actually is for most people.

And I would think as we get more and more cloud dependent any data on the phone would also be stored in company servers. So I am not sure the value a subpoenas for phones would be.

If it gets that far I would wonder if there could be a case for them of taking both personal and work phones as well just to be sure no one was talking outside of the company's standards communications.

Again I Have no idea how legally that would all go down, but I do think you being up a very good point the more speration you have between personal and work the less grounds legal action has to stand on to enter into your personal devices.

[โ€“] xavier666@lemm.ee 1 points 6 months ago

I agree but this is the next best option. This essentially creates a OS-level separation between business and personal apps.