this post was submitted on 02 Jan 2026
619 points (98.0% liked)
Technology
78435 readers
3481 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I've never used Windows - apart from new workplace requiring it. I largely not see it, unless corporate IT screws up.
Even corporate IT suffers. At my job, we have to apply updates pretty quickly. If Microsoft pushes a bad update, it'll probably affect a lot of us. Or when they add a new feature like Copilot, they ship it without any administrative controls to turn it off.
I won't deny it's godawful to have shit split across AD, Group Policy, Regedit, and Azure/Entra/Intune.
But they very much still have controls for all this shit, almost always available before the feature rolls out. I've literally never seen this shit make it through to our end user devices in an un-intended fashion.
Hell, just hold non-security updates for a period of time for review before pushing it to your entire environment if this (not actually happening) issue is a concern. That's like basic table stakes for Windows environment administration: update cadence management and pilot machines.
Please don't claim to speak from a place of authority on this and then spread falsehoods. There's plenty of shit to hate without making things up.
Like the third party app approvals in Azure and Teams defaulting to allow any non-admin user to be able to approve any azure app access to all of their data with no oversight. You can (and should) lock that the fuck down. It's a batshit default, not a lack of controls.
That's what I heard from the guys managing group policy in my org. It's been several years since I did any group policy admin.
I also remember something about Teams pushing features without control. Maybe it was when they started letting users create teams groups.
I thought one of the saving grace of windows corporate was having finer control?
The problem is Microsoft is trying to push the corporate environment away from on-prem infrastructure and into the cloud. There is less and less you can do from Active Directory and Group Policy, more and more of it gets moved to InTune everyday.
Microsoft is pushing Azure Arc as well, which is intended to let you manage your on-prem resources using your cloud management interfaces.
I don't know what this guy is smoking. Copilot had administrative controls before it rolled out, through Intune and Group Policy.