CapnPugwash Posted May 10, 2016 Posted May 10, 2016 Hi, We have O365 in a hybrid config with an on-prem Exchange server. All staff are on O365, students still on Exchange. We will be migrating the students over in the summer. I've found a few tips on things we can do to lock down parts of the students O365 accounts http://www.edugeek.net/forums/cloud-services/149382-office-365-any-areas-pupil-restrictions-we-should-aware.html But I'm interested in what I can do to lockdown OneDrive - specifically , adding file type restrictions. What is everyone else doing?
zag Posted May 10, 2016 Posted May 10, 2016 We've had onedrive for years and had absolutely no issues with abuse as far as i'm aware, it really isn't a problem. The students use it all the time to transfer work from home.
CapnPugwash Posted May 10, 2016 Author Posted May 10, 2016 We've had onedrive for years and had absolutely no issues with abuse as far as i'm aware, it really isn't a problem. The students use it all the time to transfer work from home. I want to block certain file types (.exe's etc) we have GPO's that prevent exes from running from anywhere but C:\programs GPO's can fail.
gshaw Posted May 10, 2016 Posted May 10, 2016 The more interesting one from a staff perspective is data leakage if OneDrive gets synced to personally-owned devices. Last time I checked there's no provision for this in OneDrive, short of disabling sync for all users - not sure if that's changed at all?
jamesrhart Posted May 10, 2016 Posted May 10, 2016 You can limit it with powershell so they can only sync with domain joined PCs. https://blogs.office.com/2015/07/16/new-it-management-controls-added-to-onedrive-for-business/ https://technet.microsoft.com/en-GB/library/dn917455.aspx
zag Posted May 10, 2016 Posted May 10, 2016 I want to block certain file types (.exe's etc) we have GPO's that prevent exes from running from anywhere but C:\programs GPO's can fail. Far easier to use FSRM to block executables i think.
gshaw Posted May 10, 2016 Posted May 10, 2016 You can limit it with powershell so they can only sync with domain joined PCs. https://blogs.office.com/2015/07/16/new-it-management-controls-added-to-onedrive-for-business/ https://technet.microsoft.com/en-GB/library/dn917455.aspx Bit of a pointless setting really, the domain is where we don't want to sync due to space issues on local machines. What we need is per group control of who can and can't sync data externally. Don't want to restrict students on their own devices but do need to protect confidential data staff may be storing.
jamesrhart Posted May 10, 2016 Posted May 10, 2016 Then you should probably be looking at Intune and OD4B integration
CapnPugwash Posted May 12, 2016 Author Posted May 12, 2016 Far easier to use FSRM to block executables i think. Hi, You will have to explore my ignorance here, so I can use FSRM with OneDrive? Could you point me at some documentation?
CapnPugwash Posted May 12, 2016 Author Posted May 12, 2016 Hmmm the only documentation I can find is this (from 21st Feb of this year) https://community.office365.com/en-us/f/154/t/432528?ss-src=related Where a Microsoft engineer (I presume) explicitly states "We couldn't manually restrict users from uploading files with certain extensions to their OneDrive for Business libraries or SharePoint Online sites" How is everyone else dealing with this?
zag Posted May 12, 2016 Posted May 12, 2016 Hi, You will have to explore my ignorance here, so I can use FSRM with OneDrive? Could you point me at some documentation? Nope FSRM blocks files on your file server. So whatever the kids try and download from onedrive (for example an exe) will simply be denied. 1
CapnPugwash Posted May 12, 2016 Author Posted May 12, 2016 Nope FSRM blocks files on your file server. So whatever the kids try and download from onedrive (for example an exe) will simply be denied. Ah... Like I said, excuse my ignorance. I was assuming that if the had an .exe (or some other file) in OneDrive and clicked on it, it would open from OneDrive - if they have to download to run then it's less of an issue as we use FSRM.
Tefters Posted May 12, 2016 Posted May 12, 2016 I have recently turfed over our full On-Prem Exchange to Hybrid on the fly during normal work days without issue. My school is far from perfect so here's a list of things off the top of my head that I shut down either before through my own thought or after thanks to the little sweethearts: - Disabling changing of profile picture (this is the OWA policy in the cloud), i simply moved all the kids, ran a quick PS script and then made sure the policy was default moving forward - Transport rules for things such as swear filter and also disabling of mailboxes can be a pig in hybrid config if you block students for being sh*t hats over it so we did 2 simple transport rules (inbound and outbound) with an auto-response saying "I've been a naughty student and IT have blocked me" with an exempt to staff emailing the student and just add users to that rule for a week or two to teach them a lesson (still means they can access mail from teachers but their mates royally rip the p*ss out of them when they see the message and lesson learnt). - We also did transport rules for file types (eg. SWF files) as they love to just open these from mails and play games - Restrict access to sharepoint sites however you do need the license for OneDrive - We set limits on sending to groups too - We scraped all rentention policies due to 50gb mailboxes (good luck to them filling that and if they do you can always purge in cases or just use an archive mailbox which again can go to 50gb but comes out of the 1TB onedrive space) Thats just a dump out of my head, lots more settings we tweak however just tap me up if you want more.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now