←back to thread

268 points tech234a | 1 comments | | HN request time: 0.258s | source
1. briHass ◴[] No.43516056[source]
Managing Windows devices at work using the online-first paradigm makes it clear what MS is trying to achieve here, but it's poorly communicated, as usual. In the M365/Entra world, the big benefit is having cloud Active Directory (Entra/AzureAD) and automated deployment (Intune/Autopilot) all integrated. For home users, you get bits and pieces of this, but it feels unnecessarily limited.

What MS wants (from a charitable interpretation), is the ability to encourage/enforce full disk encryption (Bitlocker), TPM-based MFA and TPM-backed passkeys (Windows Hello), as well as tight integration with their product suite (Office/OneDrive) and browser (Edge). Syncing settings, apps and other things between devices (or on setup) is also a win, though it's pretty basic right now.

Though silly to a technical crowd like HN, FDE for regular users requires a way to not lose all their data if they forget their password or some other issue happens with secure boot or the device. Non-technical users aren't going to understand the importance of backing up their Bitlocker recovery key, and without it, they're hosed. During online setup, MS stores this key online to the MS account, so it is recoverable.

MS isn't going to limit the integration and security they can provide by adhering to a local-only OS concept. It's not what most users actually want, and their competition (Apple, Android) does the same thing, so users are used to it. I just wish they had a light (inexpensive) version of the Entra/Intune package for home users that want to be able to manage multiple devices and get the real advantages of the online link.