this post was submitted on 01 Jun 2024
1018 points (97.9% liked)
Technology
58981 readers
4043 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Nah…. Just… just nah. This will never fly in enterprise environments
It won't.
All the crap from MS only affects ignorant home users. (I say that with no criticism - home users often lack significant expertise in this stuff).
Corporate has an IT team dedicated to image building, based on requirements gathering, which is well documented and well tested before it's deployed to even a small test group (usually us fellow IT geeks get to be Guinea pigs first).
Once it's been certified, then they'll deploy to a second, larger group, test and verify.
Wash, rinse, repeat.
Plus they'll probably start with new hires and anyone with a machine that is falling off lease/aging out. This gives them a little room, in that new hires don't have any local data (no one should have much in the first place), and people with aging machines can hold onto the old machine for a couple weeks as a fallback, just in case.
I've seen it several times, been part of deployment and upgrade teams.
Additionally, they deploy policies to redirect any MS network services to their own internally hosted services - windows is designed to do this, there are specific policies for everything, such us Windows Update services, even the MS App Store. Because no company wants machines pulling random crap from outside the company (they probably even block the access at the network level - I would).
Everything you’re describing is how it should be done. Realistically it isn’t done properly, all the time, and that’s why breaches happen.