Microsoft Just Killed the "Cover for Me" Excuse: Microsoft 365 Now Tracks You in Real-Time

https://lemmus.org/post/19779943

While making this easier to access isn’t a positive, there are a ton of ways that this can, and already is, being done at companies that actually care about this shit.

Yeah you’re totally in the office, but your laptop just magically has an IP from the subnet for devices connected over VPN 🙄

Once again I must insist that people need to stop expecting any privacy on work devices. It is possible to find out anything on them, including location, it’s just a matter of how much effort your workplace is willing to expend on looking.

Edit: While I appreciate the article being short and to the point, a link to any documentation on this would have been nice. The claim is that it will display the SSID of the Wi-Fi AP you’re connected to. While being able to get that from your phone is a new bit of reach, it’s possible to gather that from work devices easily.

just use vpn all the time, even when at your desk in the office
This will break a lot of applications.
This is literally how our corporate network is setup. You MUST be on vpn or you cant get to anything. Makes the access permissions super simple. Prior to this setup there were authorization settings that differed between on-prem/off, on vpn or off, which office you were in, etc. now they just deny all unless you vpn in and then it uses your vpn account to validate access there, in one place. Saved a lot of headaches.
That is certainly a direction. I hope you have robust redunacies on the concentrator.

The above is just modern network security. Thr model is called zero trust.

Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location (i.e., local area networks versus the internet) or based on asset ownership (enterprise or personally owned). Authentication and authorization (both subject and device) are discrete functions performed before a session to an enterprise resource is established. Zero trust is a response to enterprise network trends that include remote users, bring your own device (BYOD), and cloud- based assets that are not located within an enterprise-owned network boundary. Zero trust focus on protecting resources (assets, services, workflows, network accounts, etc.), not network segments, as the network location is no longer seen as the prime component to the security posture of the resource.

Google pionnered it in the 2010s I believe, but its very common now.

Zero Trust Architecture

Zero trust (ZT) is the term for an evolving set of cybersecurity paradigms that move defenses from static, network- based perimeters to focus on users, assets,

NIST
That really depends on how the VPN is setup and configured on the company side. In our case absolutely nothing breaks and it just works.
Our VPN gateway is different if you are already on the internal network.