• tty5@lemmy.world
    link
    fedilink
    arrow-up
    26
    ·
    10 months ago

    I’ve had a company require employees to install MDM on personal phones (remote control/management) to be allowed to use them for 2fa app or email access… there was a surprised Pikachu when I refused. Eventually they issued me a company phone, because it was impossible to do most tasks without 2fa. That device was on 9 to 5 only.

      • tty5@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        10 months ago

        Over 98% did. My job was security adjacent so I’ve had some insight into those metrics

        • ichbinjasokreativ@lemmy.world
          link
          fedilink
          arrow-up
          0
          arrow-down
          1
          ·
          10 months ago

          I work in IT and endpoint management is among my tasks. Knowing the things we can do to smartphones that are controlled by our mdm is enough to where I would never agree to having thatopn my personal device. I even refused to get a company provided smartphone.

    • eatham 🇭🇲@aussie.zone
      link
      fedilink
      English
      arrow-up
      8
      ·
      10 months ago

      Remote control of your personal phone for work? That sounds dodgey, I would definitely refuse. Would anyone actually accept that?

      Also, 2fa is a really shit excuse for that.

      • tty5@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        10 months ago

        Less than 2% of workforce got issued a company phone for that reason.

        Any device required MDM installed to get access to VPN that got you to company network, to get 2fa app, SSO or email.

        • Patches@sh.itjust.works
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          10 months ago

          Sounds like they’re respecting work life balance in a round-about way.

          No Boss, I didn’t get that email sent at 11 PM last night. I don’t sit in front of my PC at all hours of the day.

    • Patches@sh.itjust.works
      link
      fedilink
      arrow-up
      7
      ·
      edit-2
      10 months ago

      But why would anyone?

      I have an MDM on my work phone and I can’t even access PlayStore anymore. It only allows Company Allowed Apps which is to say nothing. YouTube is broken because MDM somehow controls my DNS records. Firefox cannot be installed so Ads everywhere. Chrome only and it can only go to approved websites because Yahoo is safe but Ars Technica is not???

      Why would anyone want that on a device they pay for?

      Is my MDM different from their MDM?

      • aicse@lemm.ee
        link
        fedilink
        arrow-up
        3
        ·
        10 months ago

        MDM can be configured in 2 modes, one with company owned devices and one with bring your own device. But there are lots of settings that can be done, usually it is configured with work and personal profiles and the work one has all the restrictions in place and the personal has no limits. Maybe just some device features can be also enforced, like forbid the OEM unlock and ADB.

    • VeganCheesecake@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      5
      ·
      10 months ago

      Why not just a physical TOTP token? There’s ones that do 100 Tokens, probably won’t need more than that. Smartphone for 2fa seems overkill.