If you, as an employee, don't want to remove TikTok I believe you will have that right, it's just that you won't be able to access company emails from that device.
Now, whether or not that leads to a company phone or you having to look for another job, depends on the individual and how important that individual is to the company.
Perhaps I'm projecting a little, but: please don't feel like you're stuck there. It's an illusion more often than not.
Of all the hills I am willing to die on, getting another phone isn’t one. Especially if they provide a credit for your cell phone.
https://www.teamblind.com/post/Amazon-Cell-Phone-Reimburseme...
I personally just bought the cheapest $60-80 Android phone from a random Amazon seller.
It falls under the category of providing your own resources to do your job, and that territory enters socioeconomic discrimination territory real quick.
But for engineers and other office workers at tech companies?
As a practical matter, people have to buy lots of things to do professional jobs that they wouldn't need to buy without those jobs. In this day and age, if you want a second phone, buying a few year old phone is cheap as is adding another phone to your existing cellular account in most cases.
And, seriously, complaining about having to spend a few bucks for something you need at work is equivalent to circumstances around Indian treaties in the US?
Of course I do have other apps directly related to work... I guess those aren't an issue if I had TikTok?
I'm with you though... If an employer wants to manage my device, they can provide the device.
The first of these could sometimes have implications for ownership of personal projects created using the device, which was one of many reasons I picked the second option, but it was absolutely permitted at least for any case where the company cared about you having mobile account access.
I even saw a guy using the code review site on his mobile, on BART. That was dumb from the standpoint of infosec, usability, and mental health, but shows how much is possible in the browser.
"""BeyondCorp began as an internal Google initiative to enable every employee to work from untrusted networks without the use of a VPN."""
Disclaimer: Googler, opinions my own.
Seriously, they could be logging your exact location, remotely activating the camera or doing any number of disgusting things.
Requiring the use of a spy should not be a factor in an employment setting, of course we're seeing this is the case and it is very offputting.
Thankfully not something I need to worry about though.
Installing an app that relays GPS and camera may be possible, but permissions need to be granted by the user explicitly- the MDM server cannot grant those permissions.
Google has in my opinion the better approach with work profile. Only give the MDM control and visibility over the work area and nothing else.
Apple has started heading into this direction with User Enrolment but it's not sufficient for most companies as it only allows built-in apps to be used for both work and personal data. And it requires Apple account federation which is problematic.
> Microsoft does the latter, so it wouldn't surprise me if Amazon does likewise.
Not true (source: current MSFT employee). More detailed explanation below, as neither former nor latter describes MSFT accurately.
So, for most teams and positions (there are many exceptions), you don't get a dedicated work phone. So yeah, if you want to access work stuff on a mobile device, you need to install MSFT MDM on your personal phone, and they will, allegedly, be able to control stuff on it (depending on the device itself and how MDM is configured).
However, there are no requirements to do it. You can simply not install any work-related stuff on your phone, so you won't need an MDM. I simply don't access any work resources on my personal phone. If I need to do work, i open my work laptop. If they want me to use work apps on mobile and be accessible, they should provide a company phone for this.
There have been zero conflicts around it on my end, even after multiple years of working there on multiple different teams. Not once have I even got an implied request from anyone (managers, colleagues, etc.) to be accessible on mobile (except for when I am on-call, but for that, they just need my phone number, not any specific apps installed on my phone, and everyone knows it) or any questions about it. Everyone is totally cool with people not being glued to their work apps on their phones on their own free time.
But you are correct, those who choose to use work apps have to give MDM permissions to their personal devices or buy a dedicated device for that (exceptions apply, because there are some teams that provide dedicated work phones). However, unless it is required for the job to be able to use work apps on your mobile device, I think it is fair if they don't provide a work phone. Makes it easier for me to not check on any work stuff during the weekend.
It turns out that I can use our 2FA app without MDM, on my personal. And nowadays, I rarely use slack or email from mobile, and I don't get calls.
I am pretty strong in the "don't put company stuff on personal devices" camp. Even if they don't control your phone by policy, they do technically. They put root certs on the device, and though they can't see individual app data (depending on config) they can see a list of installed apps, and enforce certain baselines.