<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MFA for Office365 for users refusing to use personal devices in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42018#M1230</link>
    <description>&lt;P&gt;Greetings CISOScott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your time and feedback. I truly appreciate you sharing how you and your team used a hardware based token for use with MFA. I definitely think it's the way to go! I think it is definitely our responsibility to ensure staff members know exactly how the process works and the reasons behind our push as a top priority as workers access the organizations data from any location.&lt;BR /&gt;&lt;BR /&gt;You also bring up a great point on how several other sites require the use of MFA for example most if not all banking access will require some form of additional authentication, or even big brand corporations especially after an incident occurs; the first thing they would recommend is to enable MFA for the best protection against unauthorized access. This is certainly credible information which can be used to enhance those necessary one on one conversations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Dec 2020 23:00:23 GMT</pubDate>
    <dc:creator>CISSP-Surf</dc:creator>
    <dc:date>2020-12-29T23:00:23Z</dc:date>
    <item>
      <title>MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/41991#M1222</link>
      <description>&lt;P&gt;Greetings Fellow Security Members,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently in the process of rolling out and enabling MFA for all Office365 accounts/users.&lt;BR /&gt;&lt;BR /&gt;For those who've already done so, what strategy or approach have you taken for employees who&amp;nbsp;&lt;BR /&gt;refuses to setup MFA on personally-owned devices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:44:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/41991#M1222</guid>
      <dc:creator>CISSP-Surf</dc:creator>
      <dc:date>2023-10-09T09:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/41992#M1223</link>
      <description>&lt;P&gt;RSA SecurID or a competitive One Time Password (OTP) system.&lt;/P&gt;&lt;P&gt;I realize this is more costly than sending codes to personal devices, but I believe it is a very legitimate to refuse to use personal devices for office work. Enterprises should step up to the plate and accept the &amp;nbsp;costs of doing business without trying to foist business use onto personal devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 17:11:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/41992#M1223</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2020-12-29T17:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/41994#M1224</link>
      <description>&lt;P&gt;Greetings Craig,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your time, reply, and recommendation! I think you have a good point regarding the legitimate refusal to use personal devices for office work. Enterprises should indeed look to step up and make available acceptable options as security needs change &amp;amp; arise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your insight and reply!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 17:28:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/41994#M1224</guid>
      <dc:creator>CISSP-Surf</dc:creator>
      <dc:date>2020-12-29T17:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42004#M1225</link>
      <description>&lt;P&gt;We're going through that process now but applying MFA for VPN access. Basically it was either install it for remote access or don't. If you don't install the app you lose remote access and have to come into the office to work.&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 29 Dec 2020 20:39:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42004#M1225</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2020-12-29T20:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42007#M1226</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/690706113"&gt;@tmekelburg1&lt;/a&gt;&amp;nbsp;I agree with this approach. What it really comes down to is if the company deems it wants to go with MFA to increase security, either for compliance reasons or just to enhance their security then that is what happens. A policy is made and it gets implemented. The use of a personal devices varies from company to company, some pay for the device and the bill others do not. I think it really comes down to how much the device would be used for company business. One could argue that your boss couldn't call you on your cell because that would be using it for business. It's all a matter of where you draw the line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think what is really needed to find find out why people object to is and asking them what solutions they would suggest. You can come up with a lot of different solutions but if you don't communicate that this is now required and work with them to negotiate an acceptable solution or compromise you might just end up going in circles, but if the end, this is our policy, then end!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know what other think about this, a level of acceptance is always needed but there are always those who just try to refuse changes and sadly sometimes those people may need to find a different place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my .02&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 21:28:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42007#M1226</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2020-12-29T21:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42009#M1227</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/780103681"&gt;@CraginS&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;RSA SecurID or a competitive One Time Password (OTP) system.&lt;/P&gt;&lt;P&gt;I realize this is more costly than sending codes to personal devices, but I believe it is a very legitimate to refuse to use personal devices for office work. Enterprises should step up to the plate and accept the &amp;nbsp;costs of doing business without trying to foist business use onto personal devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;We also did what Craig said. Used a hardware based token set up for use with our MFA system.&lt;/P&gt;&lt;P&gt;I will partially disagree with Craig on one point. I can agree against making them use their personal device to perform work on, like checking email, etc. but I do not see using a personal device for MFA as intruding on to their personal ground too much. I personally know of several other sites that require me to use MFA solutions like Google authenticator to access their websites. It is not that burdensome of a process. We will probably disagree or say that it opens Pandora's box of what comes next. First MFA then what? but this is just my 2 cents (opinion).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 21:32:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42009#M1227</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2020-12-29T21:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42015#M1228</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Greetings tmekelburg1,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your time and response. I appreciate you sharing your current situation applying MFA for VPN access and your approach to install it for remote access or not have the ability to utilize those technologies. I'm in 100% agreement with you from this perspective for sure.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Thanks again!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 22:35:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42015#M1228</guid>
      <dc:creator>CISSP-Surf</dc:creator>
      <dc:date>2020-12-29T22:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42017#M1229</link>
      <description>&lt;P&gt;Greetings John,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your time, response, and feedback. I think you hit the nail right on the head regarding having a clear policy in place and implementing. As you've mentioned, it comes down to how often the device would be used and where that line is drawn. I think organizations have been taking full advantage of BYOD and to properly manage and maintain the right level of security for these new "enterprise devices" a policy must be in place and communicated effectively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also as you've suggested, I did reach out to some users to better understand their resistance as well as fully explain why enabling MFA has become a standard best practice. The main points I shared include: 1) enhances security to their accounts; 2) informs them of unusual activity of someone trying to gain access to their account to access compnay data or send/receive information on their behalf without their knowledge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did offer the option to carry around an additional hardware authentication device (i.e. Yubikey) and that idea was less received than utilizing one's own mobile device for MFA setup.&lt;BR /&gt;&lt;BR /&gt;Again I think you are absolutely correct, along with clear policy messaging, some level of acceptance is required but also an additional option may be needed or provided for the small percentage who's unwilling to use personal devices for business use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your time, response and feedback!&lt;BR /&gt;&lt;BR /&gt;Nick&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 22:51:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42017#M1229</guid>
      <dc:creator>CISSP-Surf</dc:creator>
      <dc:date>2020-12-29T22:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42018#M1230</link>
      <description>&lt;P&gt;Greetings CISOScott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your time and feedback. I truly appreciate you sharing how you and your team used a hardware based token for use with MFA. I definitely think it's the way to go! I think it is definitely our responsibility to ensure staff members know exactly how the process works and the reasons behind our push as a top priority as workers access the organizations data from any location.&lt;BR /&gt;&lt;BR /&gt;You also bring up a great point on how several other sites require the use of MFA for example most if not all banking access will require some form of additional authentication, or even big brand corporations especially after an incident occurs; the first thing they would recommend is to enable MFA for the best protection against unauthorized access. This is certainly credible information which can be used to enhance those necessary one on one conversations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 23:00:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42018#M1230</guid>
      <dc:creator>CISSP-Surf</dc:creator>
      <dc:date>2020-12-29T23:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42020#M1231</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/995209551"&gt;@CISSP-Surf&lt;/a&gt;&amp;nbsp;I just feel like making a stronger point of getting their ideas. I think we have all run into situations where people simply do not like our solutions to things, and it's easy to say you don't like something but when you ask, well how would you do it, or what is a better way since you don't like mine people tend to be more agreeable because then they have to think about it and often don't have an better ideas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have always found it interesting how fast people who do not try criticize those who do!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 23:28:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42020#M1231</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2020-12-29T23:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42052#M1232</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1542574691"&gt;@JKWiniger&lt;/a&gt;&amp;nbsp;you certainly make an interesting point. It's very easy for someone to dismiss another persons solution, but asking for feedback/recommendations do make those folks think about it in a different way. I think I'll start implementing your strategy moving forward, which opens the door for deeper conversation and where I can get staff more engaged in the thought process and strategy behind our solution selections &amp;amp; implementation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm fairly confident I'll see some of the same the results you've experienced where folks are more agreeable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 00:58:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42052#M1232</guid>
      <dc:creator>CISSP-Surf</dc:creator>
      <dc:date>2020-12-30T00:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42058#M1233</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1542574691"&gt;@JKWiniger&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I agree with this approach. What it really comes down to is if the company deems it wants to go with MFA to increase security, either for compliance reasons or just to enhance their security then that is what happens. A policy is made and it gets implemented. The use of a personal devices varies from company to company, some pay for the device and the bill others do not. I think it really comes down to how much the device would be used for company business. One could argue that your boss couldn't call you on your cell because that would be using it for business. It's all a matter of where you draw the line.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;For us, it was to increase security. We typically hand out COPE, company owned personally enabled, mobile phones for workers who need to always be connected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/995209551"&gt;@CISSP-Surf&lt;/a&gt;&amp;nbsp;I haven't really thought this out long term because we would never, at least not at this point, have BYOD in our regulated environment but maybe adding an extra $5-$10 a paycheck for staff who choose to use their own devices? Just as an incentive for saving the company money.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 13:34:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42058#M1233</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2020-12-30T13:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42060#M1234</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1542574691"&gt;@JKWiniger&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think what is really needed to&lt;STRONG&gt; find find out why people object&lt;/STRONG&gt; to is and asking them what solutions they would suggest. You can come up with a lot of different solutions but if you don't communicate that this is now required and work with them to negotiate an acceptable solution or compromise you might just end up going in circles, but if the end, this is our policy, then end!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know what other think about this, a level of acceptance is always needed but there are always those who just try to refuse changes and sadly sometimes those people may need to find a different place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my .02&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1542574691"&gt;@JKWiniger&lt;/a&gt;&amp;nbsp;This part in bold will enhance any CISSP's career. If y'all do not get anything else from this conversation understand the part in bold above. Find out why people are objecting to whatever security idea, policy, procedure, whatever, you are proposing or enforcing..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe they have a misconception and think that if they have MFA on their personal phone then they will be required to do work on personal time, or that they can be tracked by the company, or that by having this on their phone it opens the possibility of their phone being seized if a lawsuit happens, etc..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen more InfoSec careers derailed by people not understanding this principle of "Seek first to understand and then to be understood" and just trying to force security on people.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Infosec is not tyranny, it is symmetry.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 14:54:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42060#M1234</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2020-12-30T14:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42063#M1235</link>
      <description>&lt;A href="https://authenticator.cc/" target="_blank"&gt;https://authenticator.cc/&lt;/A&gt; might help if it's compatible with Office365 and your security policy.</description>
      <pubDate>Wed, 30 Dec 2020 17:30:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42063#M1235</guid>
      <dc:creator>gidyn</dc:creator>
      <dc:date>2020-12-30T17:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42068#M1236</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/690706113"&gt;@tmekelburg1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hmmm I never really thought about providing some incentive for not only saving the company money long term, but also to create internal ambassadors to assist us with getting others on the same page. Thank you for sharing these insights with us!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 20:42:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42068#M1236</guid>
      <dc:creator>CISSP-Surf</dc:creator>
      <dc:date>2020-12-30T20:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42069#M1237</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/587599555"&gt;@gidyn&lt;/a&gt;&amp;nbsp;thank you for your time and feedback. We'll check this out and see what it can offer.&lt;BR /&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 20:45:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42069#M1237</guid>
      <dc:creator>CISSP-Surf</dc:creator>
      <dc:date>2020-12-30T20:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Office365 for users refusing to use personal devices</title>
      <link>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42070#M1238</link>
      <description>&lt;P&gt;I just want to take a moment to thank the newer people for contributing and starting this thread. To me, it's really why we are here, to think about things and try to think of what we could or should be doing! So thank you and please keep it up!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 21:11:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/MFA-for-Office365-for-users-refusing-to-use-personal-devices/m-p/42070#M1238</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2020-12-30T21:11:47Z</dc:date>
    </item>
  </channel>
</rss>

