Use an Official Account

Your employees should not be creating business resources in their personal accounts, generally speaking.

  1. They’re Less Secure

A work account run through Microsoft can have security measures mandated by the company’s administrator. This means there’s no circumventing 2FA! A worker cannot decide 2FA is annoying, turn it off on their account, and then get hacked as a result.

However, they can do exactly that on a personal account, and if that personal account has access to shared files, that means those files are not secured behind 2FA like they should be.

This doesn’t stop at 2FA, either. Conditional access policies allow you to secure accounts by saying “my employee is in an office located in the state of Massachussetts, ergo there’s no way they’d be trying to log in legitimately from anywhere else”, and disallow login attempts from anywhere else.

2. Even a Happy Employee Can Be Hit by a Bus

Having things linked to personal accounts for employees means that if, for whatever reason, an employee needs to be removed from the workplace’s digital ecosystem, it’s going to have to be done by blocking their Gmail address manually on each service they’re a part of. If you miss one, and the employee left on bad terms, that personal account has created a very real problem for you that you may not notice until it’s too late.

Microsoft services connect to many business services by default, and mandating using Microsoft for critical services makes blocking employees from accessing material they can’t take with them MUCH easier. Simply block them from signing in, and all of that access goes away. The same goes for employees who may have had their accounts breached – block the account, reset the password, investigate and determine how the leak happened in the first place, and then you can re-grant them sign-in permissions. With a personal account, resetting the password may take the employee calling Google and somehow verifying themselves as the account owner.

Even if you’re the best boss in the entire world, and you have the best employees ever, you’re still at risk of creating problems for yourself if you let employees use unmanaged accounts. An employee who’s hit by a bus isn’t going to be able to access their email while they’re out – if they’re JUST out. If there’s no chance of them returning, then their mailbox and all of the emails directed to it may very well be gone. With a managed account, it’s possible to recover important emails by sharing the mailbox with another employee, but a personal account is going to be much harder to get access to if such a thing is even possible at all.

3. They Don’t Look Official

Receiving an email from a Gmail address is an automatic red flag for a lot of people and vendors, especially if it has numbers and letters scattered in it. Firstly, it signals that you don’t have access to the domain level version of your name, for reasons that might be innocent, but might also be suspicious. A microbusiness using a Gmail account to secure services from a wholesaler is one thing. A small business run by one person or one family is also one thing. If the email is secured, there aren’t any additional risks to it via shared passwords, only one is needed, and they got the name they wanted, then that’s about as good as it gets for free emailing services, and a lot of vendors recognize this. Any one of those things not being true makes a managed domain better, and managing your employee’s addresses a better choice than letting them use their personal email.

Another problem with the ‘look’ aspect is that most name emails on the free services have been taken, and your employee – best case – is using some version of their given name with numbers in it to make it unique. Tricking a vendor into giving your info to some guy who claims to be your employee is much easier when your employee is JohnDorhes3921@Gmail and the scammer was using JohnDorhes3291@Gmail.

Thirdly, that JohnDorhes3921@Gmail is a best case – what if John Dorhes doesn’t have a respectable Gmail handle? What if he’s HotWheels3921@Gmail, because he’s using an account he made when he was thirteen? Will the vendor pause and consider whether or not the email’s actually good for the order it just placed?

In short, letting people use their personal addresses is a bad idea, and the best way to fix that is to use a managed domain with a trustworthy service.