databricks Databricks Blog ·

Databricks IT Details Layered BYOD Security Strategy for Personal Devices

blogsecuritydatabricksarchitect
announcement

Databricks IT outlines its comprehensive strategy for securing corporate data on employee-owned mobile devices, balancing robust protection with user privacy. The approach integrates Mobile Device Management (MDM), strong identity and access controls, Zero Trust Network Access (ZTNA), and application management. It emphasizes transparency and building employee trust by clearly defining data access and usage policies. This internal model helps Databricks empower employees to work anywhere while safeguarding sensitive company information.

  • Addressing Mobile BYOD Security and Privacy Challenges
  • Foundational Device Management with MDM
  • Layered Identity and Context-Aware Access
  • Real-time Zero Trust Network Access Enforcement
  • Securing Corporate Data Through Application Management
Notes (6)
  • Addressing Mobile BYOD Security and Privacy Challenges

    Databricks IT developed a strategy to protect corporate data on personal mobile devices without infringing on employee privacy. The approach addresses the increasing use of personal phones for work, including accessing internal apps and AI agents, where work and personal life share the same device.

  • Foundational Device Management with MDM

    The strategy begins with Mobile Device Management (MDM) to establish a trusted method for app installation and security policies. It utilizes Account-Driven User Enrollment on iOS and Work Profile on Android, creating separate, encrypted workspaces for corporate data while ensuring personal content remains private.

  • Layered Identity and Context-Aware Access

    Authentication and context-aware signals act as gatekeepers for company resources, managed through the identity provider. Access is granted only after verifying user identity with phishing-resistant MFA, confirming the request comes from a known and managed device, and ensuring it uses a trusted network path.

  • Real-time Zero Trust Network Access Enforcement

    A Zero Trust Network Access (ZTNA) solution provides continuous assessment of device health and real-time enforcement, beyond initial login. Work-related traffic is routed through a secure per-app VPN, and access is denied by default, only permitted when user identity and device health conditions are met.

  • Securing Corporate Data Through Application Management

    Application management focuses on deploying and securing managed apps to ensure corporate data remains within a secure boundary. This involves pushing managed configurations via MDM, leveraging app-specific enterprise features, or utilizing tenant-level controls to restrict actions like copy/paste outside the app.

  • Prioritizing Transparency and Employee Trust

    The success of the mobile security program relies on high employee enrollment, fostered by transparency regarding privacy. Databricks IT clearly communicates what company staff can and cannot access on personal devices, documented and reviewed with legal and privacy teams, to build trust and encourage adoption.

Read the original announcement →

https://www.databricks.com/blog/enabling-secure-productive-work-personal-devices

Related releases