PSAC 901 raises privacy concerns over cybersecurity requirements

Union encourages members to avoid Microsoft Intune

Image by: Angelina Liu
Queen’s said new measures are intended to protect University systems.

Graduate workers represented by Public Service Alliance of Canada (PSAC) 901 are raising concerns over new cybersecurity requirements introduced by Queen’s, arguing the measures could expand institutional oversight onto employees’ personal devices.

In a May 21 statement, the union encouraged members not to enrol in the University’s Protected Access model early and to avoid downloading Microsoft Intune onto personal devices unless “absolutely necessary.”

Queen’s sent an email informing graduate workers they must adopt either Endpoint Assessment or Protected Access by July 7. Endpoint Assessment provides cybersecurity protection for devices used to access University systems, while Protected Access allows eligible employees to access Microsoft 365 services without installing additional software on their personal devices.

In a statement to The Journal, PSAC 901 said, “Our members have raised serious concerns about the information collected through these systems, how these controls operate in practice, and the degree of oversight the University may exercise over privately owned devices.”

According to the union’s May 21 statement, members have also expressed concerns about privacy and the expectation that graduate workers use personal devices to perform University work. PSAC 901 said there remains limited publicly available information about how the new systems operate, what data may be collected, and how session controls function in practice.

PSAC 901 also referenced a previous grievance filed by the Queen’s University Faculty Association (QUFA) over mandatory installation of Microsoft Intune. PSAC 901 said it believes that grievance contributed to the University’s adoption of Protected Access as an alternative to full device enrolment.

READ MORE: Arbitrator partially rules in favour of QUFA in Endpoint grievance

In a statement to The Journal, Queen’s said the requirements were introduced to protect University systems and sensitive information from increasingly sophisticated cyberattacks.

“Queen’s is the target of cyber attacks on a daily basis as higher education is a rich target for organised threat actors,” the University wrote, adding that devices used to access University systems can contain or connect to personal information, research data, intellectual property, and financial records.

The University said the purpose of the requirements is to protect institutional systems and data rather than monitor individual employees. It also said graduate workers are not required to install Microsoft Intune on personal devices.

Instead, employees who choose not to install Microsoft Intune can access Microsoft 365 applications, such as Outlook and Teams, through the University’s Protected Access system, which allows users to sign in through a web browser without installing software.

Employees who need to access administrative systems, such as payroll or financial records, without a Queen’s-funded device are expected to do so through Windows Virtual Desktop, a remote computer that runs through the internet rather than directly on a personal device.

PSAC 901 also cited Microsoft’s description of Conditional Access App Control, a security feature that allows organizations to protect sensitive information by applying restrictions to users’ Microsoft 365 sessions without fully managing the devices. The union said the technology can monitor user sessions in real time and restrict actions such as downloading, copying, or printing files.

The union said the issue reflects the “increasingly blurred lines” between graduate workers’ roles as students and employees.

“Precarious academic workers should not be expected to absorb costs, risks, and responsibilities that properly belong to the employer,” PSAC 901 said in its statement to The Journal.

Queen’s said it attempted to discuss the changes with PSAC 901 through the Joint Union Management Committee before the requirements were announced. According to the University, the May 5 meeting was cancelled while PSAC 901 refreshed its committee membership following executive elections.

Following this, Queen’s said it shared a draft of the email and other communications it planned to send to employees about the new cybersecurity requirements with the union, responded to written questions from the union president, and claimed that no further concerns were raised with Queen’s leadership before the requirements were implemented.

Meanwhile, PSAC 901 said it is discussing the issue with its members, the Society of Graduate and Professional Students, and have reached out to the Ontario Federation of Labour and the Ontario Privacy Commissioner for guidance.

Since issuing its May 21 statement, PSAC 901 has not publicly announced further action beyond gathering member feedback and consulting external organizations.

Tags

Cybersecurity, Endpoint assessment, protected access, PSAC 901

All final editorial decisions are made by the Editor(s) in Chief and/or the Managing Editor. Authors should not be contacted, targeted, or harassed under any circumstances. If you have any grievances with this article, please direct your comments to eic@queensjournal.ca.

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to content