| ▲ | Xylakant 6 hours ago | |||||||
My 95% bet is that the attacker just gained access to an account with suitable privileges and then went on to use existing automation. The fact that it’s intune is largely irrelevant - I’m not aware of any safeguards that any provider would implemen. So the options here are MDM or no MDM and that’s a hard choice. No MDM means that you have to trust all people to get things as basic as FDE or a sane password policy right. No option to wipe or lock lost devices. No option to unlock devices where people forgot their password. Using an MDM means having a privileged attack vector into all machines. | ||||||||
| ▲ | neo_doom 3 hours ago | parent [-] | |||||||
No MDM just isn’t an option for most enterprises but ideally the keys to the kingdom are properly secured. | ||||||||
| ||||||||