Jump to content

Recommended Posts

Posted

I'm hoping to, finally, migrate my SharePoint 2010 to SharePoint Online by the end of the year. I have some data protection concerns though.

 

The idea is that staff will be able to work on documents at home rather than needing to be in school. This would be on personal devices for the vast majority of users. My fear is that if a documents gets downloaded onto the personal device, it is no longer controlled and anything could happen to it - resulting in a possible data breach! I've asked our DPO for advice and they said that our ICT acceptable use agreement will act as a disclaimer, so that it is their responsibility to keep the device, and all the info stored on it, safe and secure at all times. I asked if this would stand up as a defence and received no response.

 

I know about the various access control features on SharePoint Online:

Unmanaged devices restrictions isn't do-able because I don't have the required license and I need unmanaged devices to be able to access SharePoint.

Idle session sign-out I have set to log users out after 1 hour.

Network location (specific IP addresses) again I can't use this because staff will be using their home/hotel/conference/McDonalds/Starbucks connections etc.

 

There's also the O365-wide MFA option which I intent to enable, but isn't really relevant.

 

How does everyone else do this? I suppose really there is no difference than if staff download documents from their school email or encrypted USB sticks onto their personal devices.

  • 1 year later...
Posted

Hiya -

 

What did you decide in the end?

 

I'm finding that Microsoft really don't like you stopping this - Using conditional access/app enforced restrictions I can put our sharepoint into "web only mode" on unmanaged machines, but that completely breaks sharepoint externally inso much as then images or webparts also count as "blocked" so it barely functions externally.

 

https://m365techtalk.blogspot.com/2021/08/use-app-enforced-restrictions-vs-use.html

 

You can use cloud app security like that blog post says, but that... only stops downloading via the web, not if the user signs into Teams or Office suites at home. That still works fine.

 

I can kill off the onedrive sync agent to stop them en mass sync'ing their onedrives, but by default that doesn't support Azure AD joined devices, only domain joined, tho there are workarounds

https://www.azure365pro.com/onedrive-syncing-only-for-domain-joined-causing-issue-for-aad-machines/

 

But that doesn't then doesn't stop them downloading via the web

 

arghhhh!

Posted
Azure Information Protection (AIP) is quite a nice feature that solves that problem for office docs. Then you dont care about what device its on and can revoke access to the file at any time.
  • 7 months later...
Posted

Necro bump!

 

We want to use OneDrive/SharePoint in a similar way but are concerned about users saving documents to personal computers. What do others do?

I have seen a few people talking about serverless schools, how do you get around this problem?

Conditional access so only domain joined or hybrid joined computers can be used?

So many questions.

Posted

If you have E3/E5 or EMS you should be eligible for FastTrack Support who should be able to help/guide you through the options and capabilities available to you.

 

https://www.microsoft.com/en-gb/fasttrack/faqs#coreui-collapsibledrawer-5r2a3zq-collapsible-drawer1

 

Personally, we just have annual training, and termly refreshers on what is and isn't acceptable.

 

FWIW Cloud MIS's are accessible from anywhere so making 365 harder to use than that seems unnecessary.

 

 

However, if your organisation considers preventing data escaping onto private devices essential, then supply all staff with organization-owned-and-managed device, and use Conditional Access to restrict access to those only.

 

If only a subset of data needs to be strongly protected, use Labels/AutoLabels to encrypt those documents. Set the label to allow the group 'all staff' so that you block unauthenticated 'home' access, but provide a transparent experience to authenticated users. So now even if they do end up on private HDDs, they are unreadable.

Protect everything with MFA/Authenticator.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...