7 ms·
No MDM just isn’t an option for most enterprises but ideally the keys to the kingdom are properly secured.
by neo_doom 6mo ago
No MDM just isn’t an option for most enterprises but ideally the keys to the kingdom are properly secured.
- mulmen 6mo agoHow does that look exactly? Someone has to be able to use MDM to manage devices or there’s no point in having it. This scenario is firmly in rubber hose/crescent wrench cryptanalysis territory. Can updates have delays with approval gates built in? Does MDM need a break glass capability?
- heraldgeezer 6mo ago"Principle of least privilege" as MS calls it. Do not use global admin or admin account as daily driver for one. Dont save it in browser etc either. Limit roles, even within the application, here Intune. Office 365 also has conditional access and many policy leavers to tweak, many cases of people locking themselves OUT of 365. So the gates work but you need to configure them. "Break glass" global admin accounts now also require MFA. https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication?tabs=dotnet https://learn.microsoft.com/en-us/entra/identity/authenticat...
- mulmen 6mo agoOk and who has access to the global admin and how resistant are they to Iranian operatives?
- heraldgeezer 6mo agoWhat are you asking? For Stryker specifically? We don't and probably won't know details. For companies in general? Background checks, security clearance etc are done if the company determines this necessary and are willing to pay for the process and higher salary.
- pixl97 6mo agoAt the end of the day someone needs remote wipers privs, and in a large company it's something done pretty often.