6 ms·
We don't have access to that data internally. We can't access customer data outside performance metrics about the service. At least for the normal dev there i
by sabarn01 3y ago
We don't have access to that data internally. We can't access customer data outside performance metrics about the service. At least for the normal dev there is no real way to get access to what the customer does.
- gtvwill 3y agoThey can access your whole tenant and everything in it. Have had some pretty wild support calls where MSFT has had to crawl through a tenants data specifically the schedule system. It was ultra broken. They can literally just give themselves permission and roll in. If you can't your just not high enough up in a support team. Their use of 3rd party and external tools for adjusting registry during licensing problems is wild.
- sabarn01 3y agoYou can get access with customer permission for a limited time window which is audited. In the normal course of business no.
- graypegg 3y agoThe reality here is that no one will trust a pinky promise. Especially not from Microsoft. You’re fighting a good fight but it’s a losing battle no matter how locked down it feels from your POV. “Can we have access to X, but don’t worry, we don’t let anyone look at X unless Y happens” is a bit suspicious when “grant X permission when Y happens” isn’t an option. Even worse when the access to X is only disclosed to users living in a jurisdiction requiring it. Microsoft’s many brand and marketing folks have a big uphill battle if they want to convince me otherwise. Or they can just stop collecting data.
- sabarn01 3y agoLike telemetry? We have to collect customer data that's what we get paid for. As for pinky promises we are SOC compliant and externlly audited. https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2 https://learn.microsoft.com/en-us/compliance/regulatory/offe...
- JohnFen 3y ago> We have to collect customer data that's what we get paid for. Which is one of the many reasons why I will not allow Microsoft products on my machines.
- sabarn01 3y agoIf you write a document and store it in sharepoint online we have to keep that data as does any online offering.
- JohnFen 3y agoIs that what you were referring to? The phrase "we have to collect customer data" implies a different thing entirely, so I misunderstood. My objection to Microsoft's methods in this regard isn't the data that customers voluntarily and knowingly store on Microsoft servers, it's the collection of data about customers, their machines, and the use of their machines that happens behind the scenes.
- sabarn01 3y agoWe collect telemetry about user actions and the successes of our service. All the data we collect is about how the service runs and we only look at it via aggregation. Internally we have training every year about what you can and can't collect and under which scenarios. It gets stricter every year.
- graypegg 3y agoI would imagine it gets stricter every year due to this generally common opinion of Microsoft among these circles. Wish you all the best though, a Microsoft people trust would do good for the world.
- mysterydip 3y agoWhat are you using instead? Open source offerings generally work for me, it's when I have to share the results with others that formatting etc problems appear.
- jjulius 3y ago>The reality here is that no one will trust a pinky promise. Especially not from Microsoft. I'll just chime in to say that, while I appreciate the sentiment the user is conveying, I certainly don't trust a Microsoft pinky promise.
- WarOnPrivacy 3y ago> You can get access with customer permission for a limited time window which is audited. In the normal course of business no. Right but no one is saying your department is violating our privacy. I'm not sure why you feel a need to defend it. I think we can safely say that MS's methods of violating our privacy are all automated and that you + coworkers aren't eyeballing our personal data. So we can move on from that. If you'd like to speak to the privacy violations that are referenced in the article, we're all ears. Education guesses about methods or who some of the 3rd parties are would be terrific.
- com2kid 3y ago> They can literally just give themselves permission and roll in. If you can't your just not high enough up in a support team. That is what a support team is for. And those access elevations will be tracked and audited, just like at any other organization that handles sensitive data. This isn't some super duper secret, when shit breaks there needs to be a, well secured, escape hatch for the people who fix things to crawl in and make repairs. Prior to cloud hosting, Microsoft could get permissions to remote in to your servers, or prior to those days, send someone physically out with a laptop and a debugger.
- JohnFen 3y ago> And those access elevations will be tracked and audited, just like at any other organization that handles sensitive data. But surely you can see that saying this is still the same as just saying "trust us". It's very, very hard to trust Microsoft.
- com2kid 3y agoNot having those protections in place would be a company ending event for Microsoft. The legal system would crush them, and customers would leave in droves. And the number of markets Microsoft completes in now is tiny. This isn't the 90s where Microsoft competed in slews of consumer and business markets. The potential upside from the Cloud team slurping up secrets from competitors in literally ANY other business segment, is dwarfed by the losses that would hit MS. Now of course that doesn't mean some corrupt fool in sales won't risk destroying the company so he can make his yearly bonus (that very thing has brought down companies before!), but Microsoft internally has a lot of motivations to ensure that doesn't happen. So, don't trust Microsoft saying "trust us". Trust Microsoft being greedy and wanting to keep growing the cash cow that is Azure Cloud.
- JohnFen 3y agoI wasn't talking about Azure. I was talking about Microsoft's software products such as Outlook, Windows, etc. Rergardless, my point is that Microsoft saying that they have audits and controls in place is exactly the same as them saying "trust us". They're just saying "trust that we have effective controls in place".
- HenryBemis 3y agoI use an older version of "Windows Firewall Control". Regarding Outlook, I block ALL, except the server(s) that Outlook needs to contact in order to collect emails (i.e. you may have a couple of gmail accounts, etc.) The pros: Outlook doesn't get to speak to MS The cons: When an email has linked images, they don't load, which for the past 20+ years hasn't been a problem.
- zmaks100 3y agoMSFT employee here. Cannot say for the entire Microsoft, but in Azure the only way to access customer data is through support flow for cases where customer explicitly gave permissions. Otherwise support portal will not allow access. And there is no other way of accessing customer data. Access is revoked after a case is closed. The incentive for customers to give this access is simple - with this my team can answer questions right away without very lengthy back and forth (especially if customer is in different time zone). Which results in (way) faster support and problem resolution.
- wolverine876 3y agoWhat about executives and other higher-ups? If they want to know about my internal business operations - for example, if we are competitors, they are looking to invest, etc. Is there technical protection? Is it encrypted in a way that's only accessible to me?
- WarOnPrivacy 3y ago> MSFT employee here. > Cannot say for the entire Microsoft, but in Azure the only way to access customer data is through support flow for cases where customer explicitly gave permissions. That article notes that Microsoft says Microsoft accesses our data and make it available to 7xx 3rd parties. It is safe to assume that Microsoft has automated process to violate our privacy and not eyeballs and fingers. So you don't really need to defend Azure tech support because no one is accusing Azure tech support.
- WarOnPrivacy 3y agoOn one hand we have: sabarn01> We don't have access to that data internally. We can't access customer data outside performance metrics about the service. At least for the normal dev there is no real way to get access to what the customer does. On the other hand we have: Microsoft> We and 7xx Third Parties access Outlook data on user devices. Taking both you and Microsoft at face value, we seem to have two fairly different assertions. Customer concerns could be allayed if their shared data was fully auditable at any time by the customer. This would include what buyers of this data can see.
- pxeboot 3y agoOutlook (the app) is not the same as outlook.com (the email service) or Exchange Online (what most companies use). Data from one product/service could be used in different ways than others.
- WarOnPrivacy 3y agoOf course. Microsoft has different email products and services that they skim customer data from. Fortunately, Microsoft has infrastructure so robust they can share a customer's data with 733 3rd parties. I think we can safely send one more copy to the customer (who's data it is) without overtaxing anything.