5 ms·
This is a giant mess. Frankly, i don't understand how they architected it. If i open a word, excel or ppt document from another companies SharePoint because the
by ashgoyal 4y ago
This is a giant mess. Frankly, i don't understand how they architected it. If i open a word, excel or ppt document from another companies SharePoint because they added me as a guest, Microsoft promptly signs me out of the desktop office 365 apps and then says that i am using unlicensed office365.
How was this missed when designing the security and authentication systems?? This is basic foundational stuff!
- hyperman1 4y agoThat's easy to answer: It is not architected, it is organically grown. Product A adds a sign in. Product B from another team adds another sign in. Product C,D,E do the same. Each team has some special magic sauce that makes their system work better with their product, but worse with all others. Now the corporate infighting starts, as management squeezes all these sign-in systems together, and everyone looses if any other but their system wins. So some compromise is created, based more on political prowess than technical requirements. The result is an API from hell, taking fragments from everyone, even if they conflict. Everyone pushes and pulls their existing systems until it fits in the compromise, trying to minimizing damage. Weird cracks appear everywhere. we've all seen the organizational charts meme: https://www.euroresidentes.com/tecnologia/noticias-internet/wp-content/uploads/sites/5/2015/05/Organizational-Chart-for-Apple-Amazon-Facebook-Google-Microsoft-and-Oracle1.jpg https://www.euroresidentes.com/tecnologia/noticias-internet/... Remember how each organization builds a solution based on their organogram. Look at microsoft in the meme. Look at the sign in mess. Understand. I predict strange, probably exploitable and surely unsolvable problems in the MS sign-in system for at least the next decade, just like their programming practices of the '90s had entirely predictable security consequences for a decade when the internet appeared.
- hn_version_0023 4y agoThis is exactly spot-on. 20+ years of this and you have a mess of gigantic proportions.
- deleted 4y ago[deleted]
- teddyh 4y ago> Now the corporate infighting starts Typical for Microsoft, reportedly: https://bonkersworld.net/organizational-charts https://bonkersworld.net/organizational-charts
- x0x0 4y agoAnd it's crucial to understand we're well past the point where any one (or likely even a small team) knows all the places that Microsoft auth is entangled with. Thus unknown, undesirable interactions occur just because it's too big for someone to know that the interaction would occur.
- cipheredStones 4y agoThe org chart comic from its original source, instead of a random reupload captioned in Spanish and heavy on the image artifacts: https://bonkersworld.net/organizational-charts https://bonkersworld.net/organizational-charts
- twodave 4y agoI have found guest accounts in general to be barely supported. I can’t manage my 2FA for my guest account in other organizations, can’t control which account to log in with (MS seems to decide based on which resource I’m navigating to), and anytime I have an issue it pretty much takes the AAD admin removing and re-adding me to fix it. It was clearly an afterthought feature.