Jump to content

Recommended Posts

Posted

I'm finding this one a real minefield.

 

We have people who work on their personal computers at home. All our systems are cloud based now, so this is very easy to do. We can't really technologically stop this from happening and we don't particularly want to anyway because it'll reduce people's ability to work effectively. How are you all handling this? I'm not really concerned about theft; that's a pretty low risk. I am concerned about it hanging around on their hard drives in perpetuity when they leave our employment, and when they throw away their old PCs however. The only answer I can think of is a policy that says it's the employees responsibility to save all data when they're using their own computer onto an encrypted hard drive, and simply provide encrypted drives to staff who want to use their own PC at home. Probably including a secure delete tool and instructions on how to use it if they accidentally Save As > C:\...

 

Opinions?

 

Emails to phones is a further nightmare. We can remote wipe (not looking forward to raising that one...) of course, but as people can download spreadsheets etc and the "wipe Outlook data" thingy won't cover that it'd have to do the whole phone to guarantee it got everything, which I'm really loath to do. Android and iOS both have pretty good device encryption; does anyone know if there's a way to enforce that on when people connect to Exchange or something? If that was an option, I think that (in combination with the "wipe outlook data") would be sufficient. The risk is really about staff losing/selling on a phone rather than nefarious data theft.

Posted
As for Windows clients, we allow webmail (gmail) only so data cannot be downloaded.

 

I'm confused - how do you prevent them downloading attachments from GMail, or using Drive from home?

Posted
Lookign at this myself, we pretty much have decided to remove the facility to use outlook on phones and force them to use the web app and MFA.

 

In terms of usability this is a massive backward step for staff.

 

There's definitely a balance to be struck but disabling any client access and forcing only web app is a huge step and will likely see staff miss emails and use emails to communicate less.

 

At some point you're going to push their communication into areas you can't control - texts, WhatsApp etc.

 

It is possible to have mobile or client access to email and keep it as secure as required.

 

Even with web app you're not stopping them downloading attachments, copying and pasting text, taking screenshots etc.

Posted (edited)
Lookign at this myself, we pretty much have decided to remove the facility to use outlook on phones and force them to use the web app and MFA.

 

I'm not sure that's a solution. With the Outlook app it's definitely saving personal data to your device, but even if you force them to use the web app it's gonna do the same thing every time they open a PDF or a spreadsheet that's been sent to them. So I'd call that a hit to convenience without actually fixing the problems.

Edited by djrscally
Posted
In O365 Security and compliance you can select basic options such as "Require data encryption on devices" before allowing it to sync, I know InTune provides a multitude of additional options such as location based 2FA and not allowing the storage of attachments on the local device.
  • 3 weeks later...
Posted
Had a rethink and back tracked. We've setup the lovely mobile device mailbox policy via exchange and enabled MFA for OWA. Reckon thats good enough.

 

This is one of the things I am now looking at properly to get a resolution. Like you I was not entirely convinced by they built in (MDM) policies and I read these two articles last night:

 

https://support.office.com/en-us/article/capabilities-of-built-in-mobile-device-management-for-office-365-a1da44e5-7475-4992-be91-9ccec25905b0

https://docs.microsoft.com/en-gb/intune/introduction-intune

 

Just from reading these I was thinking that we may be forced into InTune to guarantee the level of security I would be happy with. Would you be able to divulge what you actually did with your mailbox policy?

Posted

There is also Policy to be considered here. It's impossible to stop it all. As long as the staff have been informed/trained to a satisfactory degree about data security when working remotely, and you have measures in place to stop the majority of unnecessary data storage outside of the security boundaries, then the staff member has a responsibility themselves to also keep the data secure. Under GDPR they can be held accountable if they go against policy and don't adhere to them etc.

 

OK, it could be bad press for the School, but at least the school should be able to demonstrate their practises, procedures and policies are rigid enough for the school not to be liable and fined etc.

 

I gave up thinking I was in control years ago :)

Posted (edited)

@leegcvcc

 

I agree but if they chose staff can sync email with any device as standard, I think preventing this and reverting back to OWA is a backwards step with how many people chose and expect to work these days. If there are reasonable measures to take to mitigate accidental data loss from syncing email then surely it must be explored.

 

Edit: I was actually going to edit my previous post with another document I found with a lot of useful information on this subject but I'll leave it here instead: http://aka.ms/Office365CA

Edited by foofighterjim
Posted

@foofighterjim

 

Totally agree. I just was mentioning that after all you've done technically to mitigate as much as you can externally, there is policy to back you up. Such as Staff should be reporting phone loss/theft etc if they sync school email onto their personal devices.

 

Sorry, I can't communicate very clearly which is a problem considering my job role :)

Posted
Totally agree. I just was mentioning that after all you've done technically to mitigate as much as you can externally, there is policy to back you up. Such as Staff should be reporting phone loss/theft etc if they sync school email onto their personal devices.

 

Ah, I'm with you now. Part of my problem is that I haven't done anything yet (except for a lot of reading). I'm still trying to figure out if Mailbox Policies, O365 MDM or InTune are the right way to go for us. I know InTune will do what we want, especially for keeping "corporate" data separate from personal even within the same app but £££.

Posted

What we did on our on-premises Exchnage box was.

 

Changed the default setting in mobile device access to Quarantined... so anyone connecting via Activesync needs to be approved (Love this)

Changed the mobile device mailbox policy to lock afer 1 minute (may change as its short) and Encryption and pin lock

Setup Azure app proxy so I can use MFA via the Azure apps portal.

 

Rewitten the staff AUP policy to include new security features and their responsibility when using emails (amongst thousands of other things)

 

I wanted to close off 443 and use the app proxy for activesync but can't. That would have made me lovely and snug

  • Thanks 1
Posted
Changed the default setting in mobile device access to Quarantined... so anyone connecting via Activesync needs to be approved (Love this)

 

Students too, or can you set that per user type?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...