Comment by 3eb7988a1663
8 hours ago
Microsoft security is a bimodal. They might have exquisite delineation for network resources in Sharepoint or Azure but consumer applications are a joke.
Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.
End users aren't expected to care about security and if they do, usually they are in an enterprise setting where it's taken care of automatically by enterprise settings.
Not to say it's good or bad, just not the target market.
End users should be expected to care about security. They should not be the only guard rail, but they are part of the defense in depth plan.
You do know about all those security training courses HR makes your take every year that you skip over?