Does your IT environment include a separate DMZ or VLAN "sandbox" for "untrusted" institutional devices, and can you temporarily use OpenRefine in an "untrusted" capacity while the Defender compatibility issue sorts itself out?
Does your IT environment support Linux (or Mac OSX or a HyperV VM Guest) and can the OpenRefine Linux (or MacOS) version meet both the CPE requirements and your needs? The OpenRefine Linux version might run alongside Windows in a Microsoft WSL2 or HyperV Linux Guest OS.
Working with institutional security requirements is a never-ending saga for developers, researchers, archivists, etc. I do understand the need to avoid costly and embarrassing security breaches, though sometimes security constraints appear rather arbitrary. Your collaborative approach is a good long term play to maintain relationships and establish a groundwork for compliant software installation in the future.
Good luck,
Wil Blake
|