3 ms·
> control over your user's device security, MDM seems like the only option. I hope that both the person to whom you are replying and their users and bosses rem
by techsupporter 3y ago
> control over your user's device security, MDM seems like the only option.
I hope that both the person to whom you are replying and their users and bosses remember that once someone has that level of control, it's not really that user's device any more.
Where I work, we debated this sort of setup, but rejected it in favor of NFC Yubikeys largely on privacy grounds. We had several employees (doctors and nurses among them, since we are a medical practice) object to a device management profile, especially because of the remote wipe permission.
Instead, we adopted Yubikeys and an automated provisioning process with a break-glass procedure if someone gets locked out.