This message was deleted.
# _general
s
This message was deleted.
r
Looking for an example of a GPO by chance?
n
We (those of us who manage the Citrix env) recently disabled the ability to sign into Chrome and sync passwords on our IT/admin desktop, as we have a corporate password management solution available for this purpose. I myself have never logged in to a browser on a company device (in my case a published Citrix server desktop) because I've never seen the need. I asked several of my coworkers if they ever signed into Chrome on a work device and they never did either, for the same reason - I concede that maybe I work differently than others.
However, changing this was (apparently) "severely impactful" for how one of our coworkers prefers to use a browser in the company environment and is proposing all sorts of potential new work so that....basically......we can allow people to sign into google/other browsers with some sort of account that allows them to sync things....on company managed devices.
I see a more simple solution of just not signing into Chrome/et al with personal accounts and syncing data, which more aligns with how company policy has always been on that sort of thing. Me personally? Why would I want my personal data/info on company stuff, I'm having a hard time relating. So what I ask is - what's everyone else doing for this? Do you allow users to sign into Chrome and the like with personal accounts to sync data? Maybe I'm way off base here and this is standard practice...but I've been around for a little bit and have yet to encounter it.
Right around the time we were rolling out these changes, I read an article about some breach that basically involved company credentials cached in a browser on a personal device that ended up getting compromised, which was used as the vector for the corporate breach.
@Ray Davis possibly, I'm sure that's where things would be defined to disable the ability to do what I outlined - a GPO is where we blocked that behavior. More curious from a practical and political standpoint the challenges people may have faced with this.
j
I nearly died on the hill, trying to defend not allowing Chrome sign-in... ultimately I lost the fight.
😩 1
a
In my experience that’s an InfoSec call. If they are happy, why would I block it if it doesn’t affect my environment?
and yes, to your point, I don’t login with personal accounts on corporate devices but users might need to login using google as IdP for third party apps/sites
n
Our infosec group is kind of out to lunch on things like this, IMO. It's hard to describe - it's usually stakeholders outside of that group driving this sort of thing. It would not surprise me if they were using non-company managed password managers themselves. Weee
j
Paging @Dave Brett
r
My approach is I have never allowed this and even advise them to lock it down. Mostly because InfoSec side would hunt me down if it wasn't blocked. I lock it down to where they can only use it for browsing. No personal sign ins, No browser add in(Extensions). Also, I don't sign in with my personal stuff into a browser on a cooperate setup either.
n
Thanks for the feedback so far everyone - confirmed my suspicions, that it's probably not standard practice to allow this sort of thing for lots of obvious reasons. Curious to hear anyone else's thoughts!
j
FWIW, we allow sync...but we configure via GPO that sync will only include bookmarks and history. we explicitly block apps/extensions
n
That's kind of what we were looking at as a "compromise", although I still think it's basically indefensible to do any of that as a matter of principle in most corp environments. Right now we're trying to query endpoints and active Citrix sessions to get a handle on just how many/what % of our users have signed into Chrome before. So far it's looking about 5% from the Citrix environment, expecting that physical endpoints will be about the same.