• 0 Posts
  • 5 Comments
Joined 8 months ago
cake
Cake day: May 17th, 2025

help-circle

  • hcf@sh.itjust.worksto196@lemmy.blahaj.zonean iconic rule-o
    link
    fedilink
    English
    arrow-up
    22
    ·
    26 days ago

    The weakest link in any system is the user, not the security policy (or lack thereof).

    I’ve seen this particular policy aggravate users to the point where they would rather export sensitive company data onto their own personal machines rather than deal with having to reauth once per hour into some Entra ID SSO-backed web app.

    Or even users who generate service account credentials that they share around with their team such that nobody uses their own account to login anymore

    When your policy teeters towards aggravating users, many of them will just find clever ways to circumvent it, which is a losing situation for everyone.



  • hcf@sh.itjust.worksto196@lemmy.blahaj.zonean iconic rule-o
    link
    fedilink
    English
    arrow-up
    76
    arrow-down
    3
    ·
    26 days ago

    If this is a login for a work/school account, it’s because someone in your IT department thinks that applying a short “max session length” policy is “extra secure”.

    Basically no different than shitty password rules or some places that make you change your password every 90 days.