Forum Discussion

OneTechBeyond's avatar
OneTechBeyond
Iron Contributor
Mar 16, 2020

Is a VPN client still recommended for Office 365 access over public WiFi connections?

To mitigate the risk of data exposure, is it recommend to still use a VPN connection, even if you are using Office 365's native desktop client apps on Windows 10? 

  • Was it ever recommended? 🙂 To mitigate data slippage scenarios, use DLP or AIP.

  • Cian Allner's avatar
    Cian Allner
    Silver Contributor
    Here is Microsoft guidance

    For VPN users, enable Office 365 connections to connect directly from the user's network rather than over the VPN tunnel by implementing split tunneling.

    This has the benefit of minimising latency, improving reliable connectivity to the closest Office 365 entry point.

    https://docs.microsoft.com/en-us/office365/enterprise/office-365-network-connectivity-principles#incremental-optimization

    In other words connect directly via the local network is preferred rather than the overhead of using a VPN, which Microsoft say should be bypassed if using a VPN. Don’t think public WiFi would change any of this guidance.
    • OneTechBeyond's avatar
      OneTechBeyond
      Iron Contributor

      My bigger concern is how do I have absolute certainty that all traffic being passed from my clients (Azure AD Joined Windows 10 Pro clients, with BitLocker on, or iOS and Android devices) to the Office 365 cloud is done completely encrypted, from at rest to in transit, even when connected to a public WiFi hotspot (i.e. captive portals at coffee shops/airports) or an untrusted network (i.e. Verizon or Comcast's public WiFi, etc.)?

Resources