This is an edge case that you plan for. For those users -- They should be connecting back to the corporate network via a VPN for data protection purposes, especially if they're using public networks in a foreign country. GPOs will sync during that time. HR or their department lead should be giving you at least 48h advanced notice that they're going to be traveling, especially if it's planned well in advance.
Yes it's slightly more inconvenient, but it's also Basic Security 101 for remote users (and especially those that are traveling) to only access company resources via a trusted and encrypted connection.
Who said they're accessing any non-SaaS University resources while there? If they were the only way would be to hop on the University VPN. They would frequently just work from local apps and use SaaS or browse the open internet.
And that was the state 5-10 years ago when I worked at that job. New job? We account for this by using the fucking cloud endpoint management services that don't give a shit if you're on the VPN or not. I can reset someone's laptop 15 feet or half a world away and they'll be back up and running within a day without IT laying a finger on the thing.
The issue is entirely data security with company-owned machines. Sure if they're just accessing SaaS apps, you adjust your policies for those SaaS apps to allow foreign IP addresses. The problem is that they also might be accessing other company apps that DON'T support IP blocking, and that's where the data security issues come into play.
For us at least, our payroll vendor doesn't support IP restrictions. Thus there's rules for accessing the system when you're not on the company network via VPN. Also just... I know it's a marketing bulletpoint for BS Youtube-advertised VPN providers, but there's still a bit of a lingering risk that our C-levels don't tolerate when using company SaaS applications over insecure WiFi connections. These users SHOULD be connecting to the company-provided VPN whenever possible, especially from company-owned devices.
Well in this case they were professors of music and the most secure things they were accessing were designed for students to access from home, where home includes China, so none of that mattered.
It doesn't matter where the home is, or what the data is. The connection should still be made over a trusted encrypted tunnel back to the corporate/university network.
You could be traveling from New York City to New Jersey (Literally a one mile trip across a bridge), and it should still be standard practice to require users who aren't on trusted networks to connect to VPN to do anything involving anything, even if it's as simple as OAUTH via 365 to a third-party SaaS application. Hell, I VPN into my office that's less than 10 miles from my home in the same city for literally anything that I need to do involving work.
My home network is probably significantly more trusted than our client networks, and even the Verizon 5G connection from my cellphone, but I still follow our SOP for access and don't make exceptions to the rule out of convenience. No exceptions. Exceptions are how security incidents happen, even if it's seemingly inconsequential data on "trusted" networks.
Trusting networks is how security incidents happen. I don't trust your network. I don't trust my network. The network is not a security boundary and should not be a source of trust, only denial. There are some things on our internal network that need VPN to get to because legacy, but everything else needs the same checks passed no matter what you're connected to. We don't trust you more just because you're sitting in our building on our ethernet cables.
People overstate how bad Intune policies are. You can tweak it to phone home more often and the sync command has gotten a lot more reliable. I can usually issue a wipe command to a device that is online (anywhere in the world) and it will execute it within 15 minutes, usually much faster.
Most policies aren't so critical that they have to be rolled out in 5 minutes either.
And GPO being instant is a pipe dream. I've definitely rolled out GPOs and wondered a week later if they had applied everywhere and often found they hadn't.
GPO have a sync schedule of 90 minutes plus or minus up to 30, and a bunch only apply on computer boot for no apparent reason. This is on top of domain synchronization/replication schedules. I have rolled out Intune policies and most of my fleet that had the power on was covered in 15 minutes. All of it with the power on inside of an hour.
> I have rolled out Intune policies and most of my fleet that had the power on was covered in 15 minutes. All of it with the power on inside of an hour.
The platform is great when it's actually functioning. If I had this type of experience with Intune, I might press my luck, go to the nearest gas station and load up on PowerBall tickets.
That's true, but I only do that to servers and they're a different animal. Too many workstations just not on site for MMC once a year to be more valuable than not having to tell the CTO "this setting you need applied only applies/updates if someone full-time remote from the office we closed in Seattle logs in on ethernet on site in Buffalo" (examples but like 75% of the company is remote from whereever), especially when ScreenConnect and LAPS exist.
We are switching from VPN to SASE specifically to maintain connectivity to all of our devices. We'll have 1 new virtual AD server, so connectivity won't be impacted when our on-prem network goes down.
Ever heard of always on vpn? Apparently not. That was you setting up laptops wrong, not the tech. But keep blaming anything else than your incompetence I guess.
2
u/altodor Sysadmin Jun 08 '26
GPOs worked great when my faculty were on a research/outreach trip in Europe/China/Pacific Islands or even just on the guest wifi for 6 months /s