Ditto Posted December 12, 2021 Posted December 12, 2021 We have a number of mobile staff who each has a work mobile phone. A predecessor set up a standard (non controlled) gmail account which everyone commonly logged into and stored each other's contact details. But, staff also stored their client contacts which should be confidential. The old issue of whether details are stored on the SIM card or the account has reared it's head, apart from the fact this approach is a really bad idea. So, the functional requirement is that a secure central administrator manages a central staff contacts list for all mobile phone users to have access to. It also think other staff would have a legitimate interest in seeing the list, but not all staff. The second requirement is for each mobile user to be able to maintain their own confidential contacts list, but we would need central admin control of those lists. I would expect for remote removal needs supporting for when staff move on. I've deliberately put this in the phone's forum rather than the M365 forum as I did not want to pre-empt the solution, but we are M365 users and I am told mobile users are usually logged in to their staff account. We do have a non-profit Google account but the Workspace functionality is not being used currently, but I'd be happy to change that. Equally, I'm open to other ideas. I guess the other factor to take on board is we don't really have a high level in-house administrator, so the solution needs to be managed day to day by someone in the HR team or an office manager. If it needs to be initially set up by an admin, we need to give clear instructions to our IT Support providers - unfortunately they are not very good with suggesting solutions or being pro-active with best practice.
jmak Posted December 12, 2021 Posted December 12, 2021 Using a shared account is obviously a really bad idea, but you knew that so I'll leave you to explain to the seniors.... As you've got a Google Workspace tenancy, but aren't using it, I'd suggest you issue the mobile phone users accounts on that and then have them login to the phones using that. It would give you a way of managing security even without setting up MDM - your galaxy is that the Google Workspace admin can change the password on the accounts used in the phone and then remotely wipe them if need be. In your situation I'd suggest that someone creates contact details in your Microsoft tenancy and then have people install the Outlook app and synchronise their contacts. If it's a big number of people, I'd put them in their own group and only give permissions to that group to see them; if it's a small number, I'd just have one person create the contacts and then share them individually with the people who need them. There are more automated ways of doing it, but if it's small scale, I think this is a reasonable compromise - you don't want to either incur a big bill from your support company or end up having to learn how to do it yourself. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now