Some common-sense arguments that go against the current industry norms. We do not necessarily recommend these approaches but for those who wish to swim against the current and go their own way these are the justifications you would make.
Local account vs Microsoft account sign in
Every new Microsoft OS revision, Microsoft makes it harder and harder for people to use local accounts to sign into Windows.
Using a Microsoft account has many benefits but essentially means that your OS is linked directly to your personal identity rather than a machine that can be used anonymously at least on a fundamental OS level.
It’s a similar argument if:
you think you should be able to use your car with your physical key(or Key FOB) without signing into a car manufacturers login screen linked to online authentication.
See the below Pro’s and Con’s of using a local account vs Microsoft Account, this is from a home user perspective but could be a very similar argument for on premAD vs AzureAD.
Local account Pros
→ Sign in activity is not being monitored by Microsoft.
→ If you do not sign into Microsoft services then there is no way for Microsoft to link you to your OS.
→ You do not need the internet to sign into your machine
→ If you need to give your computer password to someone you are not giving your Microsoft account password at the same time
Microsoft Account sign in Pros
→ Password can be reset via internet rather then just locally.
→ You can remotely manage aspects of your machine.
→ You can upload your bitlocker key to the cloud for easy reference

Local Drive encryption
Previously when a critical component failed and your HDD or SDD survived you could easily retrieve your data by simply copying the files to another machine, with the introduction of bit locker drive encryption this is no longer the case.
Now this doesn’t matter if you have the bit locker decryption key and it is sync’d to your Microsoft account, which is recommended by Microsoft. But in the real-world things that sounds easy and simply are rarely so. In the real world for one reason or another you might not have this decryption key and even though you physically have the drive your data is lost.
The question you have to ask yourself is the security worth not being able to have your data easily accessible if you physically have access to the drive. Local drive encryption stops someone from accessing the drive data if they physically have it in their hand not if it is stolen digitally from a breach.
So, you as an individual or business need to weigh ups the risk vs reward.

Not encrypting risk
Scenario: Risk of physical theft/ accidentally lost device and someone breaches Windows OS account password to maliciously steal and use data.
Likely outcome: Low risk of data breach. Most often in the real world the person who steals or finds the machine is no interested or doesn’t have the skills to crack a windows password and their main objective is to sell the device and wipe it so it can be used again

Encrypting risk
Scenario: The machine suffers a technical issue or hardware failure and the data needs to be retrieved but the bit locker key is lost.
Likely outcome: High risk of data loss, bit locker cant be be cracked unless you are a government spy agency.
Another way to phrase it, is how often is the cause of data breaches because of a physically stolen or misplaced drive vs how many come from digital data breaches,
I argue that it’s a 10 to 1 ratio. While the risk that something accidentally happens to your machine and you need to retrieve data but do not have a decryption key is much more likely in the real world.
Is data security so important for your business or required for regulatory reasons that the risk of losing data is worth the extra operational hinderance that local drive encryption introduces. This is a none debate for sensitive industries such as defense, finance, health or if you have state secrets but the same universally isn’t true for a vast number of individuals and businesses.
The argument for writing down passwords on a physical piece of paper

Do not write your password on a piece of paper, only use a password safe.
This has been a universal rule in IT since the dawn of time, do not write credentials on physical paper.
But I have a question for you, what is more like to happen these days, someone stealing your personal information digitally store in the cloud via a IT security breach, or someone breaking into your house to steal your physical birth certificate?
In this modern age its no longer a crazy question to ask what is more secure, something that is stored digitally or a piece of paper in your bottom draw? Something that can theoretically can be hacked or compromised, or a random piece of paper at in your home office buried in other equally sensitive documents such as your birth certificate?
One you have no control over and the other is a location that someone would have to physically find. The question might be easy if you are a spy or have state secrets where bad actors will plan a sophisticated heist on your home or business. But the long recognized best practice approach to not write the credentials a piece of paper but to store them digitally is arguably not the most secure approach in a totally digital world.
Now I am not advocating for passwords to be kept on a piece of paper directly in front of your machine, but even then, realistically ask yourself in modern times what is truly more at risk, your home office desk or a password stored digitally that one way or another can be compromised.
At least one option requires physical real-world access to your property.
Now even with this new logic it is never a good idea wrote down really sensitive passwords like your internet banking or main computer password on paper easily accessible in your house but we also wouldn’t recommend keeping things like that stored in your browser either.
We really just need a common-sense approach rather then just an inflexible statement advising not to write passwords on paper physically. In some ways physically storing the password on paper could be more secure in many ways.
The argument against migrating all data to cloud platforms

Using One Drive and SharePoint is convenient and has quickly become the industry standard for storing business files as it offers flexible connectivity that is not depended on a single physical resource that could fail. But the flip side is that you loose control and sovereignty of your data some negatives include:
→ If you do not have local cache of the data and the internet or the service itself experiences any issues then you will be unable to access your data, if global conflict breaks out you could lose access
→ Whatever the provider says they physically have your data and it is possible for them to use that data for their own uses (e.g. to train AI models)
→ Data stored overseas may be subject to international jurisdictions loosing your data sovereignty
→ The cost to host this data could increase throughout time and there is a possibility to become trapped in the platform/ eco system and have no choice but to pay ever increasing higher prices


Leave a Reply