Forum Discussion

Nitinsahni1615's avatar
Nitinsahni1615
Copper Contributor
Sep 28, 2024

Windows Account Sync Known wifi Network at Device level

Hi All, 

 

I am facing issue with Windows Account sync known wifi settings. This happen in the environment as feature enabled on Windows Account Settings. 

Example: New Device issue to end user and when user take this home. Home wifi is connected automatically without entering the Home wifi Password. 

Bug/Security Issue: If this was a loan laptop and Next User login to the device. This user go to known wifi Network. Under known wifi networks. Second user will see all his known wifi and known wifi of First User whom this laptop was issued. Also he can see the password of Known saved Wifi of First User. 

Observation: Known wifi information is saved/synced at device level after login to Device. Instead this information should be saved at User Level. 

Any suggestions are welcome!! 

2 Replies

  • EWilson380's avatar
    EWilson380
    Iron Contributor

    Windows allows users to synchronize settings, including known Wi-Fi networks, across devices when they log in with their Microsoft account. This can lead to the issue you've described, where subsequent users of a shared device may see Wi-Fi networks that were saved by previous users.

  • JR2021's avatar
    JR2021
    Brass Contributor

    Thank you! I can find very little information about this and it's a huge security risk and privacy concern. We are seeing users across the company gaining access to the login information of private home wireless networks (including passwords!) of other users and it's unacceptable, and there is no clear way to disable this. Maybe turning off the Windows backup for "Accounts, WiFi networks, and passwords" will work, but I assume this then forces us to disable the password keychain and other helpful features?

     

    Why? Why on earth is all of that lumped up under a single checkbox? Why isn't there at the very least a registry key to let us disable just the wireless network syncing? Why are wireless networks and passwords being shared with and accessible by every user to begin with and not just the user who added? Does this mean all of the other backed up information under that checkbox is also accessible by every user on a device?

     

    Microsoft's implementation of this has created enormous risk and vulnerability for any workers who share devices other people, and judging by the sparse amount of discussion I can find about this concern, I think most people don't even realize it.

     

    I fail to understand how anyone at Microsoft could have considered this to be a good idea, especially since they like to portray themselves as so security conscious.

Resources