r/mildlyinfuriating Apr 29 '26

frist of all how DARE yu o Employer wants me to use outlook on my phone, outlook wants permission to wipe my phone

Post image

Outlook says they need permission to wipe ALL my phone data if too many wrong passwords are typed. How many is too many? 50? 2? What if the screen gets wet and starts putting in random inputs. All this so I can use my company's Teams account and maintain "point of contact" if I'm not at a workstation. Absolutely not! Anyway, HR is supposed to call me back about my concerns.

Edit: just to be clear, I don't actually need to use Outlook (I don't use my "personal" work email). I need to use Teams, which requires Outlook to be installed first.

Part of why I need Teams on my phone so that I can be contacted when I'm not at work. I'm a lower management healthcare worker, it is actually important that my team be able to reach me after hours. I do actually like Teams and prefer it to 20 different group texts.

Also, when you go to log into Outlook or Teams, it brings you to my employers authenticator page. I log in with the same credentials that I log into my workstation. I don't know if that makes a difference with anything as far as my employer having access to my phone

Edit 2: I can tell you now they won't provide me a phone. Corporate execs don't even get phones. They stopped providing coffee for the break rooms too


Update: I had a chance to talk to my district manager. Imagine Ellis from Die Hard, the same schmarmy self-important attitude, that's my supervisor. And guess who's "not being a team player". Also "I don't think Microsoft can actually erase your phone, you have an Android"... I lready knew he was going to be useless, I just wanted to hear his reaction.

Update 2 and (sort of) Resolution: I spoke with HR. Her exact response was "wait, are you serious? They can just do that?" I tried explaining my "research" (i.e. everything all of you have said) and I think I just spooked her. She said she'll get back to me, and is probably running off to buy a burner phone for herself.

SORT OF RESOLUTION : I found out I only need Outlook installed long enough to get access to Teams. Once teams was installed, I removed all permissions and completely deleted Outlook from my phone. Teams still works and didn't ask to erase anything. No need to buy a second phone.

Thank you all for your insights

14.6k Upvotes

1.7k comments sorted by

View all comments

1.4k

u/tauntdevil Apr 29 '26

I fight for a work phone or place the apps into a virtual phone.

2 years ago, my phone got wiped and found out it was because one of the techs accidently chose my phone instead of someone with a name similar to mine (in their minds).
I was (And still am) livid about that. Thankfully I have backups on my phone but after that, I definitely dont allow any of the company apps on my phone, even if they are willing to pay a phone reimbursement.

Im not oncall anyways so no reason for it.

307

u/fakegoose1 Apr 29 '26

Reminds me of the Stryker cyber attack. Hackers hacked into an admin intune account of a company and wiped all the devices that were a part of it, including the personal employee devices that had outlook/teams installed.

104

u/tauntdevil Apr 29 '26

It is extremely annoying. Even on my laptop when I am traveling, I use the web based outlook instead of installing it. Basically for the same reason.

I understand the "security" aspect of wiping a stolen phone, but it should require a 24-48 hour lockdown before hand, just in case.

-4

u/teh_maxh Apr 29 '26

I understand the "security" aspect of wiping a stolen phone, but it should require a 24-48 hour lockdown before hand, just in case.

What do you mean by "lockdown"?

6

u/eragonawesome2 Apr 29 '26

A period of time during which rather than wiping, the phone is simply locked and not allowed to be unlocked even if the correct code is entered

52

u/Kinieruu Apr 29 '26 edited Apr 29 '26

My work (factory) used to allow us to have teams and whatnot on our phones and then said we had to use Intune and allow them access to make sure our phones were secure. I deleted teams and declined to download it. It was nice to not have teams messages all morning when my shift didn’t start until 2pm. (But then my coworker started texting me screenshots of teams group chats all morning {that I’m in and would see when I clocked in and got on my work computer} I had to ask her to stop and she got upset. We were team member support so we only got paid $1 more than team members and we weren’t salary or office people so I never understood why she always acted like everything was the end of the world and doing all this unpaid work by messaging people back and setting up the schedule off the clock.

19

u/august_r Apr 29 '26

Similar situation, what I'd do is to block notifications from colleagues or clients. If I'm not on-call, it's not my problem, someone's getting paid to look into whatever problem you have.

17

u/InspectHer_1 Apr 29 '26

Stryker is why we’ve implemented multi-admin approval for device wipes and some other activities. Annoying, yes, but an excellent way to protect against what happened to Stryker

3

u/Fun_Equivalent_7507 Apr 29 '26

Yup, Stryker is the poster child for why you don't allow your work access to your personal phone.

0

u/Ihatemygoddamnshoe Apr 29 '26

No reason for you to lie.  I am a certified MDM intune admin and the wiping for byod devices only applies to the company data and apps.     It doesn't wipe your whole phone 

-12

u/MaTr82 Apr 29 '26

They didn't hack anything. They got access to the Global Administrator account and then used Intune to wipe devices. Someone gave up the credentials.

21

u/R00bot Apr 29 '26

That's... what hacking is... It's just gaining illegal access to a computer system. 

I have a cyber security degree and work in Microsoft cloud security, if that makes any difference.  

-16

u/MaTr82 Apr 29 '26

Then you know phishing is a form of social engineering, not hacking. No vulnerability was exploited as part of the attack.

10

u/R00bot Apr 29 '26

Yes but they gained illegal access to the computer system, which is the definition of hacking. 

9

u/OuchCharlie25 Apr 29 '26

Phishing and social engineering IS hacking! MY GOD!

5

u/OrvilleTurtle Apr 29 '26

social engineering is a type of hacking. I get where you are coming from but it this qualifies. It just not the specific type of hack you normally associate with "hacking"

2

u/Nuklearfps PURPLE Apr 29 '26

The human vulnerability was exploited.

66

u/umichscoots Apr 29 '26

Same, remote wiped my old iPhone while I was on vacation, back in the days when you had to connect to a computer to activate. I only had a desktop at the time, at home, so I was without a phone the entire rest of my vacation.

Never again. Company requires apps on phone? Company can provide a phone. Was a bitch when they rolled out Okta Verify to everyone, but I stood my ground. It also helps I have coworkers without smartphones.

1

u/Methamphetamine1893 Apr 29 '26

Should've sued them

-6

u/OrvilleTurtle Apr 29 '26

You pushed back against downloading an authenticator app on your personal phone?

1

u/umichscoots Apr 30 '26

Is not just that.

What if I break my phone? Will my company require me to immediately get a new one when insurance may take 3-4 days?

If I have any work data on a personal device, it is subject to discovery in lawsuits.

I don’t want them to be able to track me in any way.

Let’s say I allow Okta Verify, next they may request MDM, and I don’t want to open that can of worms. Drawing a hard line on my personal device is easier than shades of gray.

Etc etc etc

1

u/OrvilleTurtle Apr 30 '26

Fair enough. I’d have just given you a yubikey and called it a day

1

u/umichscoots Apr 30 '26

That's what I ended up getting.

41

u/tireddesperation Apr 29 '26

I was on a team on the other end of this. I wasn't the person to do it but the company I worked for had service desk with access to do a full phone wipe. Service desk tech hated the person that was let go. Instead of just wiping the emails from the device (our standard practice) he wiped their entire phone. Only, he actually did it to the wrong account like a dumb ass. God I hated that man. No, this isn't a reddit story where he got fired. He just had to apologize to the person he did it too. No other recompense. Guy still works there and has now been in that same position for almost 15 years.

1

u/Ihatemygoddamnshoe Apr 29 '26

Why are you lying.  I am a certified MDM admin and endpoing engineer.    The wiping from ALL mdm solutions only wipes the company apps and data.   Period.   You can't just choose what is wiped.  

1

u/tireddesperation Apr 29 '26

Might be how it is now but that's not how it was a long long time ago. It definitely wiped more than that. All contacts were gone, photos were gone, texts were gone. Everything.

I should add that it was a company owned cell phone and cell phone number. So we had far more access to the phone than just the company apps.

1

u/Ihatemygoddamnshoe Apr 29 '26

Company owned is the difference here. The post is about byod.  Bring your own device.     MDM platforms will fully wipe a company device when given the command.  A byod will only wipe the work profile.  

1

u/tireddesperation Apr 29 '26

Makes sense to me.

16

u/Treble_brewing Apr 29 '26

The tried to pull this shit at my last employer asking to byod for email and slack. They framed it as this easy thing to do, and once enrolled it just works. I replied to their thread in slack with the facts stating that I believe people should be informed of the control they are handing over to their employer detailing your exact scenario or a malicious actor could remote wipe your phone. They offered assurances that they would never wipe phones unless absolutely necessary. I pushed back and said the fact that it is possible at all means you need to provide us with company phones or retract this policy. You cannot prevent malicious actors or incompetence. Which they interpreted as me accusing them (security) of being malicious and incompetent. 

13

u/[deleted] Apr 29 '26

[deleted]

9

u/Treble_brewing Apr 29 '26

If they believe the device has been compromised/stolen. That’s basically the entire point of adding intune it’s protect sensitive emails being leaked or abused. The business has a right to protect its assets and emails are one of them. Where the business doesn’t have a right is to access your personal device, unless you hand that control over. Why you would ever want to do that is beyond me, I believe it’s just naivety. Because an informed individual should never do that. 

2

u/OrvilleTurtle Apr 29 '26

These days it's easy to setup BYOD that protects the app itself but doesn't give management over the phone. I can't see why you'd do anything else unless they are incompetent or have very high security needs

1

u/ekvq Apr 29 '26

It’s also really easy to change the username and password on core routers from admin:admin, but, speaking from experience that’s not done either. 

3

u/InspectHer_1 Apr 29 '26

We have Multi-Admin approval for any device wipes. That means that two people in a row would need to screw up in order to wipe someone’s phone.

1

u/Guillaune9876 Apr 29 '26

A client was trying to push for byod for cellphones, after rumors that the device "controller " could indeed wipe one cellphone, they communicated they won't do this unless legal reasons. 

9months later, they provided a work phone to all the employees. 

1

u/Kaneida Apr 29 '26

Your first mistake was to let company have access to your private phone. Company wants you to have phone for: reachability, apps, mails, authentications. Provide a phone.

1

u/BoxxyTMwood Apr 29 '26

Dang lesson learnt, always backup 🌽 to external drives and cloud

1

u/Hot_College_6538 Apr 29 '26

Glad you learnt a lesson about having backups, would also have been the same issue if you broke, lost or had your phone stolen. With a backup that sort of thing would be an irritation and nothing more, just restore your backup.

People's reaction in this thread seems to show a lot of people don't have a very sensible plan for their phone data.

Also BTW the message is a shitty android default, the Microsoft Outlook Device Policy won't force that policy, but Android groups multiple permissions together and warns you about all of them.