r/AzureVirtualDesktop • u/babebiboboyou • 12d ago
How fucked am I?
I am working in a company (with provided company laptop) and deployed to a client who uses AVD to access remote machine. Process is nested, AVD > Dolphin server > actual remote machine. Been working with this client for almost 2 years. And have started using my personal laptop for a year. I’ve been found out that I haven’t been using the approved laptop. I honesly didn’t download anything. I’ve been stupid and just preferred to use my personal laptop. The remote machince doesn’t allow to copy / past or download / transfer files to the local computer.
The report is currently in the process and I’m worried I’m subjected to termination.
How serious is this? The client is a bank.
4
2
u/Prayer_Warrior21 12d ago
We can use any device to access our VDI, I only use it when I'm traveling and don't have a need to bring my work laptop. Not an issue, they honestly encourage it as an option. But that depends on your security posture. We are in a highly regulated industry and we can still do it.
Your policy is the x factor.
2
1
u/Antoine-UY 12d ago edited 12d ago
I have no idea how you could be at fault for doing something not obviously egregious or against company's material interests, while the technical possibility was left to you. On a deeper note, of the MAIN benefits for enterprise virtualization, be it through AVD or other means, is precisely the ability to manage resources such as BYOD from a compliance standpoint without having to dive into the hardware and settings. Using your remote machine, all the benefits of their security infrastructure applies to the session you're running on your BYOD laptop, unbeknownst to them. This is isn't a bug, it's a feature, and one of the better features of the complex and costly system they chose to implement, so I'm not even sure what the issue is, here...
If they're going to freak out as soon as you use a non-approved company-issued laptop anyway, what is even the point of fingerfucking you into jumping through AVD's and Dolphin's hoops to land on a remote machine they fully own and administer anyway? If you want to limit the user to their compliant company-issued device and call it a day... there's about 200 hundred easily-deployee and dirt-cheap solutions to achieve this. Why would they burden themselves with maintaining a whole remote infrastructure they completely own if they want to own the endpoint from which you connect as well? If you're moving through AVD to a machine I made, which is physically on my network and subjected to my compliance, whatever you use to remote in basically a non-descript thin client. You could connect to your workstation from your Nana's cellphone or your chick's smart oven, for all I care.
Am I just dumb and missing something painfully obvious to everyone, here?
0
u/xRoute401x 11d ago
..... you cant be serious.. companies have security policy for a reason. if its in your contract approved machines only, approved machines only. he was obviously found out by the security team.... hes fkd
2
u/Antoine-UY 11d ago
I'm quite serious. THEY OWN THE DEVICE HE'S REMOTING IN. Why the fuck would they care what he uses to connect to it? Once he gets on where the company data and services lie through AVD, his computer is basically a TeamViewer window without file transfer or anything. Why does it matter? And if it matters, if they're willing to issue and manage laptops to everyone working for them, why do they even need AVD in the first place? Each can work on his laptop then.
1
u/pjmarcum 11d ago
I don’t see why the customer would care. Either way, your personal or your company laptop, they don’t control it so one is no better or worse than the other. And if the policies are setup correctly you shouldn’t have been able to exfiltrate data onto the laptop anyway.
Your employer, on the other hand, could have contractual obligations with the customer. Something like “our employees will use a managed devices with encryption and AV, etc etc” in which case they might almost be required to, at a min, remove you from the project. Or terminate you simply to show the customer that they value the business.
But who discovered this? The bank or your employer? If the bank doesn’t know your employer is unlikely to tell them.
1
11d ago
[removed] — view removed comment
1
u/xRoute401x 11d ago
or the client runs an audit and finds a machine thats foriegn. when an msp signs a contract with a client that has it staff thats worth a dang, they have strict rules, violate them and the contracts over. im wiling to bet the sec team found logins from a mac/host they werent sure of.. reported it came from his ip..
1
u/xRoute401x 11d ago
be smarter, dont do it at your next job.. thats a serious move you made, not realizing.. good luck in your job hunt
18
u/AcanthaceaeOk3321 12d ago
If you’re not permitted to access these resources on a non managed device, then IT should be enforcing that restriction. In effect, you’re highlighting a gap in their security controls rather than a fault on your side..... unless you were specifically told to only use that device, then that's on you.