Hacker News new | ask | show | jobs
by gatreddi 97 days ago
If Intune wiped personal devices that’s a serious failure. BYOD setups are supposed to wipe only the work container, not the whole phone. Either those devices were fully enrolled in MDM without people realizing or someone pushed the wrong wipe policy during incident response. Would be good to see confirmation from affected employees.
1 comments

This isn't true for iOS at least. You can include device erase capabilities in the MDM profile without enrolling as a managed device.
Apple introduced User Enrollment from iOS 13 onwards, which is the preferred way to do BYOD enrollments. This enrollment type does not support the erase capability.

What you mean is the device enrollment on non-supervised devices, however and to my knowledge, enterprises do not use this, or if they do, it is very rare. (edit: And if they do, it's apparently a grave mistake.)