We have worked for almost 9 months in preparing a company-wide implementation of WIP WE. We already started migrating users to this security solution. Now all preparations (and money spent) are more or less for nothing. We also have to explain to a subset of users that their user experience will change again (!) because we have to move to a different security solution.
Our organization has had contact with multiple parties within Microsoft to explain how this impacts our organization. The takeaway from those sessions are the following:
- Microsoft does not have a solution which offers the same security as WIP WE and the same user experience (e.g. copy files to local storage and encrypt them, use Office desktop apps in a secure manner).
- We can implement different security techniques (in the Purview suite) such as endpoint DLP and information protection via sensivity labels, however we have to purchase more expensive licenses for this which isn't an option for us. Even if we would decide to do so, users will still not be able to work in the same manner as they could with WIP WE (work with secure desktop apps, encrypt local files).
- Microsoft has advised us to restrict access of users on private devices to browser only and block download to keep it secure. This however will have major impact on our users. Microsoft has explained us that this will be their strategy of the coming years; restrict access to browser only on BYOD (private) devices and give full user experience to users with managed (and secure) devices.
We still have a request on extending the WIP WE lifetime as we do not have enough time to prepare our adoption materials and configure the technical solution before the end of december. We are also still waiting for any type of compensation for the costs / effort spent.
Oh and on a more important note, they also indicated that WIP (with enrollment for managed devices) will also be removed from Windows OS build in the near future!