this post was submitted on 30 Jan 2026
227 points (98.7% liked)

Technology

79985 readers
3695 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Look, we all knew it was coming, but now it's official. Microsoft just handed middle managers the ultimate weapon. Their new update for Microsoft 365 allows companies to track exactly where you are, and the days of pretending to be at your desk are over.

you are viewing a single comment's thread
view the rest of the comments
[–] TipRing@lemmy.world 9 points 3 days ago (2 children)

This will break a lot of applications.

[–] thejml@sh.itjust.works 22 points 3 days ago (1 children)

This is literally how our corporate network is setup. You MUST be on vpn or you cant get to anything. Makes the access permissions super simple. Prior to this setup there were authorization settings that differed between on-prem/off, on vpn or off, which office you were in, etc. now they just deny all unless you vpn in and then it uses your vpn account to validate access there, in one place. Saved a lot of headaches.

[–] TipRing@lemmy.world 3 points 3 days ago (1 children)

That is certainly a direction. I hope you have robust redunacies on the concentrator.

[–] rainwall@piefed.social 6 points 3 days ago* (last edited 3 days ago)

The above is just modern network security. The model is called zero trust.

Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location (i.e., local area networks versus the internet) or based on asset ownership (enterprise or personally owned). Authentication and authorization (both subject and device) are discrete functions performed before a session to an enterprise resource is established. Zero trust is a response to enterprise network trends that include remote users, bring your own device (BYOD), and cloud- based assets that are not located within an enterprise-owned network boundary. Zero trust focus on protecting resources (assets, services, workflows, network accounts, etc.), not network segments, as the network location is no longer seen as the prime component to the security posture of the resource.

Google pionerred it in the 2000s I believe, but its very normal now. A commom deployment will have an always on vpn agent on each device, which will then use mesh vpn tech like wireguard to do peer to peer connections between the client and server. There is no need for a central vpn controller. At most their is a dns-ish directory service that runs to let each agent queiry to get public keys for the other agents. Access is gated with RBAC and ACLs.

Tailscale is well known name that provodes this model. Netbird is a FOSS example.

[–] Creat@discuss.tchncs.de 2 points 3 days ago* (last edited 3 days ago)

That really depends on how the VPN is setup and configured on the company side. And possibly how the applications it their servers are configured as well. In our case, absolutely nothing breaks and it just works.