OLdMan99 Posted June 11, 2024 Posted June 11, 2024 Hi I was wondering how you deal with staff accessing emails on their personal device , especially 0365. What sort of policy's and enforcement do you require form them. How do you stop an unlocked phone accessing emails. Seems that without some form of onboarding of an app , anybody could see email's on the device ,& this would be a data braech
Roberto Posted June 11, 2024 Posted June 11, 2024 Hi I was wondering how you deal with staff accessing emails on their personal device , especially 0365. What sort of policy's and enforcement do you require form them. How do you stop an unlocked phone accessing emails. Seems that without some form of onboarding of an app , anybody could see email's on the device ,& this would be a data braech You have a requirement to protect the data in those emails, right? So with that in mind you probably have very little choice about this, you either block access to this data from personal devices or you require some kind of device (or app) management with your MDM or MAM solution of choice. As you mentioned O365, intune would be an obvious route for this as it supports both device and application management - you can require an approved and managed device and/or app to access the O365 services, use conditional access to block access from unmanaged sources, and go from there.
OLdMan99 Posted June 11, 2024 Author Posted June 11, 2024 Is this possible using the free A1 plan & intune?
Roberto Posted June 11, 2024 Posted June 11, 2024 Is this possible using the free A1 plan & intune? Conditional Access? Probably not.
Dan2025 Posted June 11, 2024 Posted June 11, 2024 Is this possible using the free A1 plan & intune? Conditional access is included seperately within Entra P1 and also A3 for Education.
mavhc Posted June 11, 2024 Posted June 11, 2024 https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/secure-outlook-for-ios-and-android https://learn.microsoft.com/en-us/microsoft-365/admin/basic-mobility-security/create-device-security-policies?view=o365-worldwide
jmak Posted June 11, 2024 Posted June 11, 2024 Only this morning I was reading this: https://iasme.co.uk/cyber-blog/the-january-changes-to-the-cyber-essentials-scheme-reflect-the-changing-cyber-threats-in-todays-digital-environment/ All smart phones and tablets connecting to organisational data and services are confirmed in scope when connecting to corporate network or mobile internet such as 4G and 5G. [/Quote] Even if you aren't officially Cyber Essentials certified compliant, you should be following good practice. This is really easy to comply with. Option 1) configure and enforce conditional access Option 2) prohibit access to organisational information on personal devices If SLT complain, tell them they need to spend the money. If users complain, send them to SLT. 1
Olliedawg Posted June 11, 2024 Posted June 11, 2024 We only have A1 & if staff want their emails on a personal mobile device, they must register their device to our Intune (install company portal app, device must be compliant). Allows you to revoke access / remotely wipe etc.. Conditional access policies would be nice, however dont get these on A1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now