Microsoft security is a bimodal. They might have exquisite delineation for network resources in Sharepoint or Azure but consumer applications are a joke.
Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.
End users aren't expected to care about security and if they do, usually they are in an enterprise setting where it's taken care of automatically by enterprise settings.
Not to say it's good or bad, just not the target market.
> Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.
Because years of experience has shown that even users who should know better (developers) get extreme permission fatigue. The demand end users make is "it should just know without me having to click 'approve' all the time." Well, that's tough. You're basically stuck between a rock (fine-grained permissions) and a hard place (don't make me deal with it).
Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.
Not to say it's good or bad, just not the target market.
You do know about all those security training courses HR makes your take every year that you skip over?
Because years of experience has shown that even users who should know better (developers) get extreme permission fatigue. The demand end users make is "it should just know without me having to click 'approve' all the time." Well, that's tough. You're basically stuck between a rock (fine-grained permissions) and a hard place (don't make me deal with it).