Securing Remote Workers: VPN, MFA, and Device Management
Security & antivirus
remote work
VPN
security
endpoint
MDM
By Cade · Updated 03/05/26 07:41 AM
Remote workers introduce security challenges: devices on home networks, personal devices mixed with work data, and lack of physical security controls present in the office. A layered approach addresses these risks.
Essential controls: MFA on all accounts (especially email and VPN — the most attacked entry points), VPN for accessing internal resources (split tunnel VPN so only internal traffic routes through VPN, reducing latency for internet traffic), and MDM (Mobile Device Management) to enforce device security policies.
With Microsoft Intune, enroll all company-owned (and optionally personal) devices to enforce: disk encryption (BitLocker/FileVault), screen lock (max 15 minutes), OS updates (require minimum OS version), and approved app installation. Conditional access policies can block access to Microsoft 365 from unmanaged or non-compliant devices. Train remote workers on home network security: change default router passwords, use WPA3 Wi-Fi, and never connect to public Wi-Fi without the VPN.