How should we secure browser-only SaaS access on contractors’ personal PCs?

0
0
Asked By MellowCedar42 On

We have about 50 offshore customer-service contractors using their own Windows PCs from various countries, including the EU. Their work is entirely browser-based and mainly involves Google Workspace, Shopify Admin, and Zendesk.

We would like to avoid issuing corporate hardware or fully enrolling personal machines in MDM, but we still need to:

- Require access through a protected browser or isolated workspace
- Block downloads, printing, and copy/paste of customer data where practical
- Revoke access immediately when a contractor leaves

Our current idea is Entra for identity, Intune app protection for an Edge work profile, and Conditional Access requiring an app protection policy. However, the documentation seems focused on Microsoft 365, and we are concerned that third-party SSO applications may not work reliably.

For teams in a similar situation, what worked best: Edge MAM, Defender for Cloud Apps session controls, an enterprise browser, browser isolation, Azure Virtual Desktop or Windows 365, or something else? What problems did you encounter with less technical users working from different countries? In particular, did Google Workspace sessions or Drive for desktop create unexpected data-leak risks?

4 Answers

Answered By NorthwindBasil6 On

Be careful about treating copy/paste blocking as real data-loss prevention. If a person can see the information, they can potentially photograph the screen, transcribe it, or use another device. These controls are still useful for preventing accidental or casual leakage, malware transfer, and unaudited downloads, but they will not stop a malicious insider. Stronger protection also means limiting what each contractor can see with least-privilege roles, masking sensitive fields, restricting exports, and exposing only the data needed for the job.

CopperMeadow24 -

If they do not need broad access to the underlying customer systems, consider a narrowly scoped application or API workflow instead. Reducing the amount of data displayed is more effective than relying only on clipboard controls.

Answered By CloudyRook53 On

Full Intune enrollment may be technically stronger, but it can be difficult to justify on personally owned devices, particularly across multiple jurisdictions. App protection and conditional access are worth testing, but do not assume that a policy documented for Microsoft 365 will seamlessly protect every third-party SaaS application. A practical design is often a managed identity plus MFA and geo restrictions, with the actual data confined to VDI or an enterprise browser. Document the privacy boundary clearly and verify the offboarding process end to end.

AmberWillow19 -

The privacy and legal side matters as much as the technology. Device seizure, forensic collection, monitoring, and personal-data access can be restricted on BYOD systems, so confirm the requirements for each country before choosing MDM.

Answered By SilverMango31 On

An enterprise browser or remote browser-isolation product can work if you want something lighter than a full desktop. Look at products such as Island, Chrome Enterprise Premium, Cloudflare Browser Isolation, or similar platforms that support identity-based policies, download and print blocking, clipboard controls, and session revocation. Test the complete workflow before committing: third-party SSO redirects, browser extensions, password managers, file uploads, Google Workspace behavior, and support for contractors on inconsistent home networks.

Answered By QuartzHarbor7 On

The cleanest boundary is usually Azure Virtual Desktop, Windows 365, or another VDI platform. Keep the SaaS sessions inside the hosted desktop, disable clipboard, printing, drive redirection, and local file transfer, and do not install Drive for desktop on the personal computer. Tie access to MFA, country-based Conditional Access, and the contractor’s identity so offboarding disables both the account and the hosted workspace. This also gives you better logging and avoids pretending that a personal Windows installation is trusted.

PineLattice88 -

The Drive sync client is especially important to exclude. Browser access can be controlled reasonably well, but syncing company files to a personal endpoint destroys much of the isolation.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.