Jump to content

Recommended Posts

Posted

Hi all,

 

We have been assigning staff members Pro Plus for Faculty licenses from our Office 365 so they can install and use Office on home computers. However I have just discovered that when they do this it gives that home PC access to the staff members email, one drive etc without any authorisation.

 

I did this by going into Word, Account, Manage Account. From here I can gain access to the staff members Office 365. Not ideal as it might not always be the staff member using the home PC.

 

Any idea how we can stop this?

 

Regards

 

Jim

Posted
Its by design - the license is assigned by the account that is logged into office so it assumes that you want Outlook configured for that account too.
Posted
You could request that staff sign out of the Office account if it's on a shared computer. Just means they would have to sign in each time they wanted to use it so it reactivates
Posted
Any idea how this works with Controlled Access (add-on to Azure AD which lets you limit O365 access to domain machines)?
Posted
You can limit access to Office 365 to an external IP but you'll break email on phones. Really you need conditional access and intune MAM and WIP to safeguard your organisations data. It depends if you want to block office 365 externally.
Posted (edited)
Unfortunately we can't afford all three. I was happy that using Conditional Access gave us the protection we need, but hadn't worked out that it would stop people from accessing email too. Staff also currently benefit from being able to download the Office client to personal machines and I guess that will go too. Edited by jmak
Posted

Conditional Access can provide for all the access you need/ and what you don't at a very granular level.

 

For example, block access to untrusted PCs for outlook, but allow webmail and activesync accesss. You can allow access to download the office suite and install it, but block access to onedrive.

 

What untrusted means can be a little trickier, it might just be setting a rule and excluding the IP range that you access office365 from. It could be 'if the computer can see the internal interface of ADFS (if you use it). Or it could be the machine has intune agent or Azure AD Hybrid/ Domain joined

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...