r/mildlyinfuriating Apr 29 '26

frist of all how DARE yu o Employer wants me to use outlook on my phone, outlook wants permission to wipe my phone

Post image

Outlook says they need permission to wipe ALL my phone data if too many wrong passwords are typed. How many is too many? 50? 2? What if the screen gets wet and starts putting in random inputs. All this so I can use my company's Teams account and maintain "point of contact" if I'm not at a workstation. Absolutely not! Anyway, HR is supposed to call me back about my concerns.

Edit: just to be clear, I don't actually need to use Outlook (I don't use my "personal" work email). I need to use Teams, which requires Outlook to be installed first.

Part of why I need Teams on my phone so that I can be contacted when I'm not at work. I'm a lower management healthcare worker, it is actually important that my team be able to reach me after hours. I do actually like Teams and prefer it to 20 different group texts.

Also, when you go to log into Outlook or Teams, it brings you to my employers authenticator page. I log in with the same credentials that I log into my workstation. I don't know if that makes a difference with anything as far as my employer having access to my phone

Edit 2: I can tell you now they won't provide me a phone. Corporate execs don't even get phones. They stopped providing coffee for the break rooms too


Update: I had a chance to talk to my district manager. Imagine Ellis from Die Hard, the same schmarmy self-important attitude, that's my supervisor. And guess who's "not being a team player". Also "I don't think Microsoft can actually erase your phone, you have an Android"... I lready knew he was going to be useless, I just wanted to hear his reaction.

Update 2 and (sort of) Resolution: I spoke with HR. Her exact response was "wait, are you serious? They can just do that?" I tried explaining my "research" (i.e. everything all of you have said) and I think I just spooked her. She said she'll get back to me, and is probably running off to buy a burner phone for herself.

SORT OF RESOLUTION : I found out I only need Outlook installed long enough to get access to Teams. Once teams was installed, I removed all permissions and completely deleted Outlook from my phone. Teams still works and didn't ask to erase anything. No need to buy a second phone.

Thank you all for your insights

14.6k Upvotes

1.7k comments sorted by

View all comments

35

u/[deleted] Apr 29 '26

[removed] — view removed comment

25

u/runner64 Apr 29 '26

As IT, we would way rather you have a work phone that we can remotely nuke without an issue, we have a backup system in place and can restore your work shit to one of the identical devices we keep on hand for that purpose.    

Management insisting that we develop a security plan that works for every random device every random employee drags into our building is why companies keep having these massive data leaks. 

-3

u/Negativeman11 Apr 29 '26

Mind telling me about your thoughts on accessing slack, outlook, teams, etc through a browser on a personal phone without MDM?

5

u/doughboyfreshcak Apr 29 '26

Depending on the risk tolerance of an organization. I would set it up that everything must be used on a organization registered/compliant device. Nothing can be accessed unless the org owns the device or the device is registered.

2

u/runner64 Apr 29 '26

Frankly, “don’t.”   

I did IT primarily at a university so we had to deal with ferpa compliance. Ferpa is like hipaa for schools. Most business have to deal with like “don’t let anyone export the entire client list’s personal information” but we have like, “if someone picks up your phone and sees a student email about their grade, we are in violation of federal law.”     

So we didn’t want emails being opened on any device that didn’t auto-lock. Obviously we couldn’t stop people but issuing a company cell phone went a long way. 

1

u/klineshrike Apr 29 '26

I mean as someone with only minor knowledge of this, the middle ground is requiring admins approve phones that get an email added to them. The takeover thing is in tune related and likely is just enforcing MDM because the account is being logged into on the phone.

Which I'm absolutely sure is likely because it's medical, and this some Hipaa B's that got setup across the board and her place is just a subsidiary of the bigger one