63 points

These people really don’t know how MDM solutions work.

permalink
report
reply
2 points

… actually they aren’t wrong. MDMs are given special permissions including but not limited to reading your SMSes and phone records, restricting and monitoring your installed apps and even wiping your device.

permalink
report
parent
reply
19 points
*

Please cite any one of your sources. I’ve managed MDM for over a decade and you’re spreading misinformation.

Absolutely none of the MDM products on the market allow for the reading of personal e-mail, SMS, phone records, etc. On the contrary, almost every single one provides an information screen during the enrollment that makes it abundantly clear that they do not (and can not) access that data. Moreover, the “wipe” of data is the removal of company data. It doesn’t wipe your phone, it just removes the work profile (Android) or deprovisions the work profile and associated apps (Apple). All of your non-work-related data is untouched.

Quick Sources for Intune and JAMF – do your own googling for others:
https://learn.microsoft.com/en-us/mem/intune/protect/privacy-data-collect
https://www.jamf.com/blog/apple-mobile-device-management-faq/

permalink
report
parent
reply
15 points
*

Absolutely none of the MDM products on the market allow for the reading of personal e-mail, SMS, phone records, etc.

So you’re not aware of Sophos’s MDM offering? That explicitly states they can make copies of all SMS messages?

https://support.sophos.com/support/s/article/KB-000034436?language=en_US

How about call logs, with SureMDM?

https://knowledgebase.42gears.com/article/how-to-view-call-logs-on-android-phones-remotely-using-suremdm/

Also I said nothing about personal emails.

Moreover, the “wipe” of data is the removal of company data. It doesn’t wipe your phone, it just removes the work profile (Android) or deprovisions the work profile and associated apps (Apple). All of your non-work-related data is untouched.

No, the ‘wipe’ can be a full factory reset.

https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe

Edit: typo

permalink
report
parent
reply
46 points
*

I’m not sure what MDM you’re subjected to but I’ve been an MDM engineer for 7 years using Intune and JAMF and no, no SMS or phone records. Even the phone # is blanked out minus the last 4 digits. Yes we can wipe the devices if it’s lost\compromised but personal versus corporate owned devices are limited. I can’t see what apps you have that were personally installed. And the only info I can get are the device stats (SN, IMEI, storage, battery, memory, etc).

permalink
report
parent
reply
37 points
*

Can you support your claims? I’ve worked with Intune, Jamf, MaaS360, Citrix, and Workspace ONE and none of them could read texts, emails or browser history.

I’d be very interested to learn more about how they can access this information through MDM. We always did it through either the mobile carrier or the admin console for whatever the office/mail suite that was deployed.

permalink
report
parent
reply
11 points

Can you elaborate? I have simple mdm on my work phone and would like to know exactly what they see and can do

Not that I am hiding anything. It’s more curiosity at this point

Posted from my personal phone

permalink
report
parent
reply
10 points

This depends on the configuration of the MDM and the MDM vendor. For example, most MDM deployments to Android for instance conform to Android For Work, which functions in practice to a virtual machine from a user’s perspective, and doesn’t have access to a non workspace content. iOS has a similar functionality which, while less commonly used, is there specifically for use on personal devices to sandbox off ‘work’ content where pervasive features like factory resets and access to phone logs and sms records don’t function, and you can’t access the more advanced features without having purchased the device via a corporate account.

SimpleMDM has a credit card-less trial which you could set up to see what features exist and how they work from the vendor side. You won’t have access to some of the ‘supervised’ features without being a business,but you can see the buttons offered when you aren’t a corporate-purchased device readily enough.

For corporate owned devices, the rules are very different though.

permalink
report
parent
reply
3 points

I can’t read your emails, text messages, I can’t remote into your phone without your permission. The info we have is very limited. You know how we can see that information? If you gave us your phone and password :-)

permalink
report
parent
reply
3 points

So if the info it provides is very limited, why are companies pushing for it? Why should I install it on my personal phone so I can access Teams and Outlook?

permalink
report
parent
reply
8 points

I have a little experience with Microsoft’s intune and there are different ways to register devices. Someone feel free to correct me because I don’t feel like logging in to double check. Company owned devices have more control and can restrict apps, lock, full wipe, etc. Personal or “bring your own” devices are much less restricted. I can’t lock, wipe, or restrict apps. For the personal devices, it’s more about giving secure access to the companies resources and not really controlling the device. I work for a small business and only use this to setup access to non important documents for employees in the field so I know just enough to be dangerous.

permalink
report
parent
reply
27 points

This is a woefully misinformed post…

permalink
report
reply
-1 points

Separate profile and container. Idiot meme.

permalink
report
reply
7 points
*
Deleted by creator
permalink
report
reply
2 points

Tell me you didn’t read past the first line without telling me.

permalink
report
parent
reply
33 points
*

It depends how the MDM is implemented. If it allows locking and wiping the entire device, no. If it makes a sandbox for the work stuff, and it only grant them access to control, lock and wipe that sandbox then I don’t mind.

That’s what we do for personal devices, corporate devices are fully managed/supervised.

permalink
report
reply
0 points

Yeah I don’t care about having a work profile.

Also there are cross the wall permissions in the special permissions in the settings in Android

permalink
report
parent
reply
14 points

Software is imperfect and you shouldn’t trust that future updates will not add that ability.

permalink
report
parent
reply
5 points

Typically, the app needs to ask for permissions like that, though. On Android, they need to ask to become a “Device admin”, and they need to specify what specifically they’ll use that access for. I imagine (though I’m unsure since it’s never happened to me) they need to ask to update those permissions if they want their uses to change.

permalink
report
parent
reply
3 points

Agreed, but its not perfect. I recall but couldn’t recover a link to a story about some application bypassing android or iPhone permissions.

Another big recent flaw allowed apps without the permission to draw over other apps.

https://blog.checkpoint.com/research/android-permission-security-flaw/

permalink
report
parent
reply
16 points

Yeah my work MDM is setup this way with Android Enterprise. Everything work-related is isolated to that area and there is no other access to the full device. I can even have all those apps shut off after-hours or when on vacation so I don’t get notifications during personal time. My boss knows to text/call me if there is something urgent that comes up.

permalink
report
parent
reply

People Twitter

!whitepeopletwitter@sh.itjust.works

Create post

People tweeting stuff. We allow tweets from anyone.

RULES:

  1. Mark NSFW content.
  2. No doxxing people.
  3. Must be a pic of the tweet or similar. No direct links to the tweet.
  4. No bullying or international politcs
  5. Be excellent to each other.
  6. Provide an archived link to the tweet (or similar) being shown if it’s a major figure or a politician.

Community stats

  • 7.7K

    Monthly active users

  • 1K

    Posts

  • 45K

    Comments