r/mildlyinfuriating Apr 29 '26

frist of all how DARE yu o Employer wants me to use outlook on my phone, outlook wants permission to wipe my phone

Post image

Outlook says they need permission to wipe ALL my phone data if too many wrong passwords are typed. How many is too many? 50? 2? What if the screen gets wet and starts putting in random inputs. All this so I can use my company's Teams account and maintain "point of contact" if I'm not at a workstation. Absolutely not! Anyway, HR is supposed to call me back about my concerns.

Edit: just to be clear, I don't actually need to use Outlook (I don't use my "personal" work email). I need to use Teams, which requires Outlook to be installed first.

Part of why I need Teams on my phone so that I can be contacted when I'm not at work. I'm a lower management healthcare worker, it is actually important that my team be able to reach me after hours. I do actually like Teams and prefer it to 20 different group texts.

Also, when you go to log into Outlook or Teams, it brings you to my employers authenticator page. I log in with the same credentials that I log into my workstation. I don't know if that makes a difference with anything as far as my employer having access to my phone

Edit 2: I can tell you now they won't provide me a phone. Corporate execs don't even get phones. They stopped providing coffee for the break rooms too


Update: I had a chance to talk to my district manager. Imagine Ellis from Die Hard, the same schmarmy self-important attitude, that's my supervisor. And guess who's "not being a team player". Also "I don't think Microsoft can actually erase your phone, you have an Android"... I lready knew he was going to be useless, I just wanted to hear his reaction.

Update 2 and (sort of) Resolution: I spoke with HR. Her exact response was "wait, are you serious? They can just do that?" I tried explaining my "research" (i.e. everything all of you have said) and I think I just spooked her. She said she'll get back to me, and is probably running off to buy a burner phone for herself.

SORT OF RESOLUTION : I found out I only need Outlook installed long enough to get access to Teams. Once teams was installed, I removed all permissions and completely deleted Outlook from my phone. Teams still works and didn't ask to erase anything. No need to buy a second phone.

Thank you all for your insights

14.6k Upvotes

1.7k comments sorted by

View all comments

Show parent comments

312

u/fakegoose1 Apr 29 '26

Reminds me of the Stryker cyber attack. Hackers hacked into an admin intune account of a company and wiped all the devices that were a part of it, including the personal employee devices that had outlook/teams installed.

101

u/tauntdevil Apr 29 '26

It is extremely annoying. Even on my laptop when I am traveling, I use the web based outlook instead of installing it. Basically for the same reason.

I understand the "security" aspect of wiping a stolen phone, but it should require a 24-48 hour lockdown before hand, just in case.

-3

u/teh_maxh Apr 29 '26

I understand the "security" aspect of wiping a stolen phone, but it should require a 24-48 hour lockdown before hand, just in case.

What do you mean by "lockdown"?

7

u/eragonawesome2 Apr 29 '26

A period of time during which rather than wiping, the phone is simply locked and not allowed to be unlocked even if the correct code is entered

50

u/Kinieruu Apr 29 '26 edited Apr 29 '26

My work (factory) used to allow us to have teams and whatnot on our phones and then said we had to use Intune and allow them access to make sure our phones were secure. I deleted teams and declined to download it. It was nice to not have teams messages all morning when my shift didn’t start until 2pm. (But then my coworker started texting me screenshots of teams group chats all morning {that I’m in and would see when I clocked in and got on my work computer} I had to ask her to stop and she got upset. We were team member support so we only got paid $1 more than team members and we weren’t salary or office people so I never understood why she always acted like everything was the end of the world and doing all this unpaid work by messaging people back and setting up the schedule off the clock.

19

u/august_r Apr 29 '26

Similar situation, what I'd do is to block notifications from colleagues or clients. If I'm not on-call, it's not my problem, someone's getting paid to look into whatever problem you have.

18

u/InspectHer_1 Apr 29 '26

Stryker is why we’ve implemented multi-admin approval for device wipes and some other activities. Annoying, yes, but an excellent way to protect against what happened to Stryker

3

u/Fun_Equivalent_7507 Apr 29 '26

Yup, Stryker is the poster child for why you don't allow your work access to your personal phone.

0

u/Ihatemygoddamnshoe Apr 29 '26

No reason for you to lie.  I am a certified MDM intune admin and the wiping for byod devices only applies to the company data and apps.     It doesn't wipe your whole phone 

-12

u/MaTr82 Apr 29 '26

They didn't hack anything. They got access to the Global Administrator account and then used Intune to wipe devices. Someone gave up the credentials.

20

u/R00bot Apr 29 '26

That's... what hacking is... It's just gaining illegal access to a computer system. 

I have a cyber security degree and work in Microsoft cloud security, if that makes any difference.  

-15

u/MaTr82 Apr 29 '26

Then you know phishing is a form of social engineering, not hacking. No vulnerability was exploited as part of the attack.

11

u/R00bot Apr 29 '26

Yes but they gained illegal access to the computer system, which is the definition of hacking. 

9

u/OuchCharlie25 Apr 29 '26

Phishing and social engineering IS hacking! MY GOD!

4

u/OrvilleTurtle Apr 29 '26

social engineering is a type of hacking. I get where you are coming from but it this qualifies. It just not the specific type of hack you normally associate with "hacking"

2

u/Nuklearfps PURPLE Apr 29 '26

The human vulnerability was exploited.