Jump to content

Recommended Posts

Posted

We have always allowed staff to get school email on their personal devices. Should it be enough to have a policy that states Staff need to have a passcode on their device if they access School emails or should we implement an MDM solution that forces it?

 

If we have an MDM solution that enables remote wiping of Data does this only wipe data that relates to the School account?

Posted
We have always allowed staff to get school email on their personal devices. Should it be enough to have a policy that states Staff need to have a passcode on their device if they access School emails or should we implement an MDM solution that forces it?

In terms of DPA, the law says : "Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data."

 

IMO that means you should do both. You should have good policy that informs them about Data Protection issues and you should ensure your users understand and accept the consequences of any technical measures, i.e. remote device wipe etc.

 

What is more difficult is the way apps can interact with data on a device. So if you have (say) whatsapp and it starts processing your contacts and inviting you to add them as whatsapp contacts; strictly speaking that should be a breach of DPA. IMO it is questionable that users can be entirely responsible for this. In the same way as we need to warn them of device wipe, we need to be aware of the potential consequences and deal sensibly with the risks.

Posted (edited)
What are you using for email? Outlook does this automatically, and I believe gmail does this too

Gmail

Both 365 and G Suite allow you to wipe phones that have email apps connected. I think Exchange does as well.

 

I know that Gmail allows you to wipe data from phones but I wanted to know if it only wiped Data related to the School account or did it wipe the phone entirely?

 

Actually I found out;

 

https://support.google.com/a/answer/173390?hl=en

Edited by fiza
Posted
In terms of DPA, the law says : "Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data."

 

IMO that means you should do both. You should have good policy that informs them about Data Protection issues and you should ensure your users understand and accept the consequences of any technical measures, i.e. remote device wipe etc.

 

What is more difficult is the way apps can interact with data on a device. So if you have (say) whatsapp and it starts processing your contacts and inviting you to add them as whatsapp contacts; strictly speaking that should be a breach of DPA. IMO it is questionable that users can be entirely responsible for this. In the same way as we need to warn them of device wipe, we need to be aware of the potential consequences and deal sensibly with the risks.

As MDM solution would solve this as you can implement managed apps for devices

Posted
As MDM solution would solve this as you can implement managed apps for devices

Aye, but staff will feel loathe to give us that level of access to their devices (I believe even in non supervised mode iOS gives you pretty high permissions) Also not sure if you can enforce this on Office 365, e.g disallow outlook access unless MDM installed

  • Thanks 1
Posted
Aye, but staff will feel loathe to give us that level of access to their devices

 

That was the impression I got when I brought the up issue of having MDM for personal devices.

Posted
You can enforce device policies via exchange so stuff like needing a pin on the phone before they can add their work account and the like. Its a balance of protecting your organizations data and allowing users the freedom of being able to consume that data on the devices they want. At the end of the day you have the need to be able to protect the data and they have the option of being able to access their data as long as its in line with the policies you have set out in your information security policy. I have seen just how emotive this issue can be but it needs handling with care and as along as you keep people informed most will generally accept that its a necessary requirement and is for the protection of them as individuals as well as for the organisation (and needs top down support!).
Posted

Just a slight tangent - how do you know the device is suitably wiped when they upgrade and recycle their old phone or give to family or friend? I'm not too sure that all staff would inform you their personal phone was lost or stolen, let alone when they upgrade it themselves.

 

JB.

Posted
Sometimes there is no technical solutions! but you should use impossible travel and the likes to help identify this sort of thing.

Sorry you lost me. 'impossible travel'?

Posted (edited)
So you can use Azure to identify if a user is logged into more than one device that are too geographically far apart for the user to be able to be physically logged in to those device/ have been able to travel the distance between locations. Edited by HPlum78
  • Thanks 1
Posted
So you can use Azure to identify if a user is logged into more than one device that are too geographically far apart for the user to be able to be physically logged in to those device/ have been able to travel the distance between locations.

 

Not sure how effective that would be for us - our MDM thinks devices in school are in Hyde Park, so we'd get "impossible travel" alerts every time a staff member goes home or turns the wifi off and uses their 4G.

Posted

Subscribing to this thread. I suspect with the rollout of G Suite that some of our more engaged staff will want to have their Google accounts linked to their own personal phones. Most of them probably won't, but a few might.

 

The main issue is that these are personal devices, so we won't be able to remote wipe the whole thing, but if there's some way we can at least wipe the GMail box/disassociate the account, that'd be good. Just in case.

 

Note to self: Find out what happens with the GMail app if there's a change of password

Posted
Note to self: Find out what happens with the GMail app if there's a change of password

 

We have SSO to our AD, so it might be different, but for us, the apps continue to work even after a password change. Disabling the user in AD stops the apps from authenticating though.

Posted (edited)

Loooooong post, but hopefully contains enough info to be useful. Bit of a detail-dump though. I'd have uploaded screenshots but I don't have a USB-C cable at work.

You can safely skip this post if using GMail/G-Suite doesn't apply to you.

 

 

I've just tried to add one of my a test accounts as a second account on my phone in the GMail app and been given the message:

This account requires mobile device management. To satisfy the security policies associated with the account, you have to install a newer version of the Google Apps Device Policy App.

I'm given the option to skip this, but if I do, I'm not able to view the inbox. It just hangs on 'Getting your messages...'

 

If I install the update I get:

This application allows administrators to enforce policies on how your mobile device is used to access work information. If you are using Gmail or Google mobile apps for personal reasons, you don't need this app.

To keep your data secure, it also allows the admin to remotely wipe data, while you can reset your screen lock code remotely or locate a lost device.

Some device details will be shared with administrators.
[VIEW DETAILS]

Using this application is subject to the Google mobile terms of service and the applicable G Suite terms of service for your organisation.

 

The 'View Details' button displays:

Domain administrators can view these details about your device:

Device Model: ONEPLUSA3003
Serial Number: REDACTED*
Device ID: REDACTED*
Operator: EE
Device OS: Android 7.1.1
Build number: REDACTED*
Kernel version: REDACTED*
Baseband Version: REDACTED*

Domain administrators may request a list of applications accessing domain data.

* (actual data is shown, not the word REDACTED)

 

Clicking 'Next' from the 'This application allows administrators....' page prompts up 'Allow Device Policy to make and manage phone calls?'. The Google Apps Device Policy app then requests to be activated as a device administrator, which allows it to:

[list]
[*]Erase all data
[*]Change the screen lock
[*]Set password rules
[*]Monitor screen-unlock attempts
[*]Lock the screen
[*]Set the device global proxy
[*]Set screen lock password expiry
[*]Set storage encryption
[*]Disable cameras
[*]Dsiable some screen lock features
[/list]

 

If you click Activate this device administrator you are given the following:

The following domain policy settings will be enforced:
[list]
[*]Device password must be set
[*]Administrators will be able to remotely wipe the device
[*]Administrators will be able to remotely remove account* from the device
[*]Administrators will be able to remotely provision Wi-Fi networks
[/list]

You can do the following actions on your device:
[list]
[*]Locate device on a map
[*]Ring your device at high volume
[*]Reset your device password/PIN
[*]Lock your device
[/list]

* sic erat scriptum

 

Clicking 'Enforce' then finishes the setup, and my test account started getting calendar events and emails coming through.

 

I am still (as a user of the phone) able to initiate a factory reset (at least, it asks for my PIN/fingerprint, I didn't complete the process.)

 

So if I login to G Suite as my Superadmin account and make my way to that users' information page, there's a category under 'Account' labelled Mobile devices which gives me the option to wipe the account off device, or wipe the entire device.

gsuitemobile.png

 

If I change the password on that account, my phone brings up an alert saying:

⚠ Google Play services
Account Action Required
email@domain

and no longer delivers mail for that account to my phone.

 

If I click on the alert, I get:

email@domain
You were signed out of your Google account. Sign in again to continue.

and am prompted for the new password. Sign back in, emails again, standard stuff.

 

It is worth noting here that I could still view emails already delivered to the phone whilst I was locked-out.

 

Clicking the 'Wipe Account' button on the user information page returns This account will be remotely wiped during the next sync.

gsuitemobile2.png

 

Once this happens, my phone gets an alert reading:

Device Policy
Account wiped
A domain administrator has wiped account email@domain from this device using Device Policy. This device is no longer being administered using Device Policy.

As this alert implies, the 'Google Apps Device Policy' app has also removed itself from the device Administrators list. It has not been removed from the phone, though.

 

I have an old OnePlus One I'll test the wiping with when I get home, but I can't see why that wouldn't work.

 

 

TL;DR: To add a managed G Suite account to an Android phone, the user must download an app and have it set as a device administrator. That says it gives a tonne of permissions over the device (which it technically does), but the only options the G-Suite Admin actually gets are to remove the account from the device, or to wipe the entire device.

 

HTH :)

Edited by Garacesh
  • Thanks 4
Posted

@Garacesh That's really great, thanks.

 

One follow-up question on the data wipe - did it just remove the test account or all data? Obviously, lots of staff will have personal Google Mail accounts on their devices, which I'd rather not wipe.

Posted
@Garacesh That's really great, thanks.

 

One follow-up question on the data wipe - did it just remove the test account or all data? Obviously, lots of staff will have personal Google Mail accounts on their devices, which I'd rather not wipe.

 

Um.

Perhaps?

:p

 

I didn't actually test that because my test account doesn't have much data on it (drive, etc), I really just tested emails.

From the messages it gave, I'd assume it would remove the account from Drive/Keep/etc. My suspicion is, however, that anything that's been downloaded to the phones own internal storage will not be effected by this.

 

I'll create a few bogus spreadsheets and stuff when I'm testing the full wipe with my OPO tonight and report back. (Or a bit earlier with my OP3, if I get a slowdown before 4pm)

And I don't have any iOS devices to test this on. Sorry!

Posted

Follow-up post to the earlier G-Suite/Android dump. Ignore if not relevant to you.

 

So I fired up my old OPO and linked it to my test account. I created 2 files in Drive, one spreadsheet which was made Available Offline and one document that wasn't, but was downloaded locally. Despite the document not being available offline, I could still access it via the Docs app, presumably this is a cached copy. So what's the difference? I have no idea. I could edit both documents, and both were sat there 'Waiting for network'. Perhaps the Available Offline option effects actual computers more than the smartphone apps. Upon reconnecting to the wifi, changes were synced back upstream. So as expected, nothing will happen to a handset that is (for example) stolen and the Wi-Fi and Cellular signals are disabled. Obviously an account wipe cannot be initiated either. But the device will likely have cached files on that can be read.

 

What I was able to do with the all wireless comms disabled is go into the phone settings, then Accounts, and turn off all syncing for the work account (App data, calendar, contacts, docs, drive, gmail, google fit data, people, sheets and slides). That said, if I were in a position to get disable this lot, I could just remove the Policy app from the Device Administrators list.

I initiated the account wipe whilst all syncing was disabled on the phone and all wireless comms were off, re-enabling wireless comms after-the-fact. The account was still immediately blocked, then wiped, even with all syncing options turned off.

 

So from this we can establish that syncing cannot be disabled in order to keep the account from being removed (syncing an account in-general can probably be disabled in some custom OS builds, or by using a firewall app but that's typically way beyond the capabilities of our users).

 

I lost access to the spreadsheet that I had enabled offline availability. I did not lose access to the document I had downloaded to local storage.

 

I was able to reconnect the same device to the same account without an issue. Handy for if a phone is found again, but worth remembering that if you remote-remove an account, you should enforce a password reset too!

 

Once the account was reconnected I initiated a full device wipe. This immediately rebooted the phone and set it into 'Erasing...'. I held the power button in to force the phone off, then turned it back on again. It continued erasing. The full-device wipe also wiped the SD card.

 

Additional: I was not able to remove the lockscreen security or revert to the insecure 'Swipe to unlock.' Both options displayed the message Disabled by administrator, encryption policy or credential storage. I was able to select Pattern, PIN or Password. Presumably phones with fingerprint and facial/iris recognition will have those options enabled still, too.

  • 3 weeks later...
Posted

@Garacesh I have just started down this road for a small primary school. Which setting is it that I need to enable in Google admin that will display the following message

 

This account requires mobile device management. To satisfy the security policies associated with the account, you have to install a newer version of the Google Apps Device Policy App.

 

Also does it take the users to the Device policy app so they can install it?

Posted (edited)
@Garacesh I have just started down this road for a small primary school. Which setting is it that I need to enable in Google admin that will display the following message

Not a clue. I assumed that the message/requirement was inherent to all enterprise-grade/managed accounts. Have you tried connecting one of your managed accounts to an android device and not received the message, or have you not tried signing in yet?

 

Also does it take the users to the Device policy app so they can install it?

No, it's one of Google's core services AFAIK so it just automatically downloads it when needed. It does require the user to manually set it as a device administrator, though if I remember rightly if you refuse to then it won't deliver emails/sync calendar/allow Drive access/etc

 

Edit: I only know about Android atm, I have no iOS device to test this on though as the last member of staff to leave handed back his iPad and didn't take his account off it so I can't wipe it or do anything. I'll do another big ol' infodump after Christmas when some more of our staff leave and I get an iPad I can screw around with.

Edited by Garacesh

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...