Parent epic: #41
Goal
Produce the security and privacy design that must be reviewed before Device Guard accepts any remote policy write.
Scope
Model the complete flow between the account owner/device custodian, delegated filtering administrator, read-only support, release/operator staff, web console, identity provider, management service and enrolled device.
Cover at least:
- abusive or mistaken administrators;
- stolen accounts and sessions;
- malicious or cloned clients;
- invitation theft and unauthorized ownership transfer;
- replay, downgrade and stale-policy attacks;
- service, signing-key or operator compromise;
- insider access and cross-tenant data exposure;
- denial of service, offline devices and clock manipulation;
- compromised or replaced devices;
- privacy abuse through excessive inventory, telemetry or audit data.
Document every collected field, purpose, legal/operational basis, retention, visibility, export and deletion behavior. The default design must exclude browsing history, message or contact content, location, screenshots, app content, local PINs, recovery codes and device credentials.
Complete the applicable Israeli privacy and accessibility review before customer deployment.
Acceptance criteria
Non-goals
- Implementing telemetry or the management service.
- Treating a generic cloud threat model as sufficient for Device Owner policy control.
Hebrew summary
לפני פתיחת ניהול מרחוק יש למפות מי יכול לתקוף או לנצל את המערכת, איזה מידע נאסף, מי רואה אותו, לכמה זמן הוא נשמר ואיך מוחקים או מייצאים אותו. אין לאסוף תוכן אישי או קודי שחזור כברירת מחדל.
Parent epic: #41
Goal
Produce the security and privacy design that must be reviewed before Device Guard accepts any remote policy write.
Scope
Model the complete flow between the account owner/device custodian, delegated filtering administrator, read-only support, release/operator staff, web console, identity provider, management service and enrolled device.
Cover at least:
Document every collected field, purpose, legal/operational basis, retention, visibility, export and deletion behavior. The default design must exclude browsing history, message or contact content, location, screenshots, app content, local PINs, recovery codes and device credentials.
Complete the applicable Israeli privacy and accessibility review before customer deployment.
Acceptance criteria
Non-goals
Hebrew summary
לפני פתיחת ניהול מרחוק יש למפות מי יכול לתקוף או לנצל את המערכת, איזה מידע נאסף, מי רואה אותו, לכמה זמן הוא נשמר ואיך מוחקים או מייצאים אותו. אין לאסוף תוכן אישי או קודי שחזור כברירת מחדל.