Jump to content

80-90% of all compromises originate from unmanaged devices


Recommended Posts

Posted (edited)

This statistic from Microsoft's Digital Defense Report 2023 gives me the shivers as many schools, ours included, allow students and staff to access data in 365 from unmanaged devices.

 

I'd be really interested to learn from schools who have decided to only allow access to 365 data from managed school devices, or who have managed to implement device management controls on BYOD devices and how this has been received by users.

Edited by gybe78
Posted
You're not alone! There are so many things in that report that would be relatively easy to fix in a corporate setting that are so difficult to get senior management to agree to in a school - MFA for pupils? Providing corporate owned and managed devices for all staff and pupils? Or forcing staff/pupils to enroll their personal devices into a managed device solution?
Posted

If I was feeling ungenerous I'd quip that 80-90% of compromises involve a Microsoft email account at some point too, on the attack and/or target side. I can't cite any actual stats, but it feels about right.

 

We're not big users of M365 here, and so our licensing doesn't include the sorts of security features that Microsoft will be promoting as essential in order to actually operate securely. Conditional access and endpoint verification stuff will help to allow 'safe enough' use of unmanaged devices, I should think. Like "refuse sign-ins from devices with an unsupported OS". I, too, would be interested to here from those who are actually doing this stuff.

Posted

We have A3 licensing so can do some of this stuff, like conditional access forcing MFA for staff or blocking access by location, but it's only "safe enough" until it isn't I suppose.

 

MS are shifting or creating a lot of their advanced security stuff into higher tier licensing models or add-ons which is annoying.

Posted
We have A3 licensing so can do some of this stuff, like conditional access forcing MFA for staff or blocking access by location, but it's only "safe enough" until it isn't I suppose.

 

MS are shifting or creating a lot of their advanced security stuff into higher tier licensing models or add-ons which is annoying.

 

Yeah I'm in limbo at the moment because we were about to move to MFA then Microsoft moved the goalposts, so currently re-evaluating the options.

Posted

Seems very hard to enforce unless you hand out devices to staff and students 1:1 , which would make life a lot easier, perfect world would be a phone and laptop for everyone.

Wonder if all the Mcafee expired trials would cause an issue for our students and staff

Posted (edited)
Just setup conditional access. We've done it to lock down to the UK and a couple of other types of devices. Works very well.

 

We have conditional access policies in place to protect user login. But currently a genuine user can login to 365 services on an unmanaged device which is unknown and untrusted. If the device is riddled with malware then data in 365 is at risk.

 

I've just come across App Protection Policies in Intune which go a long way to mitigating risk on non-MDM enrolled iOS and Android devices, but it doesn't address unmanaged Windows devices (as far as I understand it).

Edited by gybe78

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...