Kinda dump question

Posted by StrikingPeace@reddit | sysadmin | View on Reddit | 65 comments

We connect user's personal cellphones on the same subnet that we connect work issued laptops So the phones can reach production servers The reason for connecting them is to simply grant wifi access on their personal cellphones for emails, whatsapp etc and some printing for very few people probably 1% I'm thinking this is a security risk the cellphones should be on a separate subnet or vlan that cannot reach the production servers, as we obviously don't have control over their personal cellphones How do you handles this in your orgs or would advise to