How should we secure browser-only SaaS access for contractors using personal PCs?

0
0
Asked By MellowQuill47 On

We have about 50 offshore customer-service contractors using their own Windows PCs from various countries, including the EU. Their work is entirely browser-based, mainly Google Workspace, Shopify Admin, and Zendesk. We want to avoid issuing corporate hardware or enrolling personal computers in full MDM where possible.

Our goals are to require access through a protected browser, restrict downloads, printing, and copy/paste of customer data, and revoke access immediately when a contractor leaves. One option is Entra ID with Intune app protection for an Edge work profile and Conditional Access requiring an app protection policy, but the documentation seems focused on Microsoft 365 and there are concerns that third-party SSO applications may not work reliably.

For teams in this situation, what worked best: Edge app protection, Defender for Cloud Apps session controls, an enterprise browser, VDI or Windows 365, browser isolation, or another design? What caused problems for less-technical users in different countries, particularly with Google Workspace sessions or Drive for desktop?

4 Answers

Answered By CedarFox_82 On

The cleanest boundary is usually AVD, Windows 365, or another cloud desktop rather than trying to make a personal Windows installation trustworthy. Keep customer data inside the hosted session, disable clipboard, printing, local drive and USB redirection, and do not install Drive for desktop on the contractor's computer. Offboarding can then disable the identity and the cloud desktop together. Use MFA, country-based access policies, logging, and sensible session controls as well.

BrightMango6 -

I would especially keep Drive for desktop out of scope. Browser access can be controlled reasonably well, but a sync client on the personal machine immediately undermines the data boundary.

Answered By QuietHarbor19 On

An enterprise browser or remote browser-isolation product may fit if a full desktop is too expensive or cumbersome. These tools can apply identity-based policies and restrict downloads, printing, clipboard operations, and sometimes screenshots while leaving the contractor's normal operating system unmanaged. Test the complete workflow first, though: Google authentication, Shopify and Zendesk SSO, uploads, file previews, password managers, extensions, and recovery from expired sessions can all behave differently.

CopperLime31 -

Treat the controls as protection against accidental or casual leakage, not as a guarantee. Once data is displayed on a user's screen, someone can photograph it or manually transcribe it.

Answered By SatinOrbit5 On

If the business truly needs strong endpoint assurance, avoiding device enrollment is the part to reconsider. Intune enrollment can enforce patching, screen-lock settings, encryption, endpoint protection, and compliance before access is granted. Whether that is acceptable depends on the employment arrangement, local privacy law, and your ability to support and eventually investigate personally owned devices. Get the legal and privacy requirements settled before choosing the technical control.

AmberKite_28 -

Personal-device forensics and seizure can be difficult or unlawful in some jurisdictions, so a hosted desktop often gives a better separation between company data and the user's property.

Answered By VelvetPanda73 On

Also question whether contractors need direct access to the underlying customer systems at all. Fine-grained roles, masked fields, restricted views, and a task-specific application or API can expose only the information needed for each job. That reduces the impact of a compromised account more effectively than relying on copy/paste blocking alone. Whatever architecture you choose, disable local synchronization, use short-lived sessions and MFA, restrict access by approved countries where practical, and have an explicit offboarding test.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.