Jump to content

Recommended Posts

Posted

Sorry folks I've been away and downed all tools.

 

The problem we're experiencing, is users adding the OneDrive app to their mobile device, the results being accessing corporate content on their personal devices mobile devices. We're keen to stop and are currently not sure if this is doable in the Security and Compliance section.

Posted (edited)

@Mr_Jiminy

 

This is one area where OneDrive \ SharePoint on O365 are really lacking imho - very little granular control over where data ends up. MS were trying to sell me down the InTune route but don't think even that will give us the level of control that's really needed i.e.

 

- allow usage of OneDrive (as 1TB storage per user comes in very handy!)

- control access to sync functions per security group (not global)

- control which devices are allowed to sync OneDrive data i.e. only those with BitLocker enabled

 

What with Delve and OneDrive MS are making data much easier to find but at the same time much easier to lose or give access to people who shouldn't have it...

Edited by gshaw
  • Thanks 1
Posted

Smells like yet another Microsoft money making scheme to me... Which on the one hand I understand, whilst on the other I think could be provided without rinsing it, selling add-ons for something that should already be tenant integrated.

 

We've tightened up on our email/ cloud services AUP documentation - making staff fully understand the risks and how to prevent a mess in a tea cup (so-to-speak).

Posted
Rather than disable it, why not make sure that personal devices containing corporate data are secure? Try Office 365 MDM:

 

https://support.office.com/en-gb/article/Capabilities-of-built-in-Mobile-Device-Management-for-Office-365-a1da44e5-7475-4992-be91-9ccec25905b0

 

Passcode policy, force encryption, selective and full device wipe. Ticks all the boxes.

That's the next port of call for our smartphone users, although it doesn't seem to address users syncing OneDrive on a Windows PC as far as I can tell?

Posted
That's the next port of call for our smartphone users, although it doesn't seem to address users syncing OneDrive on a Windows PC as far as I can tell?

As far as I know it's just iOS, Android and Windows Phone devices. Not sure how you would go about enforcing it but could require users to encrypt their laptops with Bitlocker if they want to sync OneDrive or have company data on it.

Posted (edited)
As far as I know it's just iOS, Android and Windows Phone devices. Not sure how you would go about enforcing it but could require users to encrypt their laptops with Bitlocker if they want to sync OneDrive or have company data on it.

 

That's where Microsoft need to get their act together and make the Windows client MDM compatible for all OS (I know 10 is moving in that direction but many users won't be on that despite MS worst efforts). Should do something like this:

 

- user tries to sync OneDrive library

- client checks for policy from O365 based on the domain

- client is told by MDM policy that sync should only be allowed on encrypted devices

- app queries OS to check if BitLocker enabled on sync destination drive

- if BitLocker not enabled then deny sync

 

Given the time it took to get a sync client that even worked properly I imagine the above isn't happening anytime soon but it really needs to. At the moment it seems to be a fairly blunt setting that only allows sync to domain-joined PCs, better than nothing I guess but not very flexible.

Edited by gshaw

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...