Either by accident, or just defaults getting increasingly more tight, Outlook won't connect to the account unless I allow it to be a device administrator.
On my personal phone, that's a hard no. So I'm using the PWA for the occasions I NEED to check email.
But a TOTP app of my choice, implementing a standard RFC protocol? I think that's okay, on the condition that it does not mean my phone is in scope for any regulations the company is mandated to adhere to.
I agree that's a hard no for personal devices though.
On Android you can define a device as corporate owned, which mean the employer have full control over the device, or it can be user owned and instead of taking control of the entire device, it makes a sandbox in which the corporate data resides, and the mobility admin can only touch what is inside that sandbox. If the phone is lost or the employee leave the business, you can remotely wipe the sandbox while leaving the user data untouched.
IMO this is a better approach, but it depends on how the system is set up.
It's nice having some flexibility for the different mindsets, but as long as the tools are provided by the employer when they're mandatory I don't see a problem.
I'm not going to turn that sandbox on when I'm not at work.
That allows the line between self-owned work and employer-owned work to be thin/non-existent.
That can make it a lot easier for your employer to own your personal projects.
Don't do it. Don't use your corporate laptop for personal things, and don't use your personal equipment for corporate things.
If they want to use 2FA, they need to provide the 2FA device.
As a regular employee, I am just unlikely to refuse the employer's silent requirement to use my own device to log in into their systems. Hell, some companies have even started promoting BYOD (Bring Your Own Device), which is wrong on so many levels.
What’s that gonna achieve when entire firm has zero trust policy?
Any kind of third party internet required app? Do I required Microsoft Authenticator or Duo - always on push access, internet required, logs my phone's IP and location? They must pay for the device and the plan. If you want me enter MDM, Outlook, ActiveSync? They must pay for the device and the plan.
That being said, TOTP is practically standard and every phone have a method of generating their own TOTP so I don't mind adding employer's company to my BitWarden or Apple passwords. Same way I would not have problem to have SMS as a MFA.
Also it's gross, I hate giving out my number
If anyone is doing that in 2024, that is a warning sign.
I had them give me a phone. It sits on my desk. 99% of 9he time, it's used only for Microsoft Authenticator. (That does not count the seemingly endless "Scam Likely" calls I simply ignore.)
But yes, my policy is to absolutely never use personal devices for work, and vice versa. Complete and total separation. The laptop I use for work was paid for by my employer.
- Offer people a cell phone stipend, which the employee may or may not accept.
or:
- Issue a security key.
We choose to go with "We are issuing you a security key, bbbbuuuttt you can choose instead to use your phone at your discretion."
In the case of something like TOTP, though, I wouldn't insist that they provide a phone to use for it because it works without talking to any servers (unless I don't have a smartphone, of course).
My concern is to keep my employer's business and my personal business off of each other's systems. So if there's a requirement to use an app or to interact with company systems, then my employer needs to supply the equipment necessary to do that.
Employers should provide a dedicated 2fa device (maybe a phone) if the employee wants but I can't think of the security case for employers to need to control / remote wipe the 2fa device since they could lock the account it is providing access to.
The hassle of carrying an extra device, charging it, storing it and taking care of it is exactly that: a hassle.
But, do note that we were talking about a phone for 2FA and you're talking about a phone for on-call. I'm too senior for on-call, but I need 2FA daily.
I work in Finland and in all the jobs I've hard for Finnish companies they've either offered to pay for a new phone for me, or offered to pay my phone bill if I kept my personal phone.
Generally I don't actually do anything work-related on my phone, I just use Duo and Okta apps for logins, and have a 2FA application for some site-specific logins.
In the worst case I would be prepared to be fired over this issue.
It doesn't have to be a phone, though. Yubikey is good and affordable.
A) provide a phone. B) pay for part of my personal bill; but no MDM allowed. C) be ok with me not always being available. I enter the job like this. I state I am also a firefighter, if I don’t answer, I’m involved. Managers can manage.
(I don't use it for anything else but auth, of course)
In fact, this should itself be a law.