I’ve had a good think about this, and while it’s good to see them finally answering bubblewrap, the truth is that we as an industry have been ridiculously at permissioning for some time and this does not solve this. It’s all very well saying we have read only resource access, but then you connect up to JIRA and all of a sudden you’ve got a different identity system, different resource model and and more complexity than you can shake a stick at.
Our current answer of just making the security model more and more complex isn’t working. It just means that, when things inevitably fail, we can say “well, they didn’t secure it correctly”. When even describing what is correct is hard, and setting it up is harder.
Honestly, this looks good, but we need a root and branch rethink of security if we want something that can protect us from rogue agents.
Microsoft security is a bimodal. They might have exquisite delineation for network resources in Sharepoint or Azure but consumer applications are a joke.
Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.
Seriously. Mobile devices have done a better job with this (in some ways) but it really should be a standardised thing of least permissions by default. And way. Way less confusing.