Jump to content

Recommended Posts

Posted

Hi,

 

I am wondering what other schools do in relation to the OneDrive Client?

 

As in, do you control what devices can install and use the OneDrive client:

 

- School Domain Devices Only

- Personal Devices Denied

- Personal Device Allowed (/ combined with Condition Access Rules)

 

 

Whilst there are numerous controls that can be put in place to manage schools devices (e.g. KFM, Files on Demand, SharePoint Resources online only via OneDrive client) all these are not available once using a personal device. Of course, Conditional Access Rules could be used to a degree but ultimately I am thinking of the situation where, most likely a staff member, has synced resources from SharePoint and they are all stored locally on their personal device.

 

One of the biggest issues is the the SharePoint 'Sync' option, which although you can remove this option, by doing so breaks links to those resources using the OneDrive Client (but not online version).

https://techcommunity.microsoft.com/t5/sharepoint/want-sharepoint-online-users-to-use-add-shortcut-to-onedrive/m-p/3194536

https://stackoverflow.com/questions/68028076/hide-sync-button-but-allow-add-shortcut-to-onedrive-in-sharepoint-online

 

Thanks,

Posted

Morning

 

We block OneDrive client sync on personal devices and only allow in-browser access to 365 data. It took a while to fine tune our CA rules but I think we've got it covered now.

  • Thanks 1
Posted
Morning

 

We block OneDrive client sync on personal devices and only allow in-browser access to 365 data. It took a while to fine tune our CA rules but I think we've got it covered now.

 

Would you mind sharing your CA policy for this?

Posted (edited)
Would you mind sharing your CA policy for this?

 

Sure. Hope the below makes sense.....

 

 

NAME: Use app-enforced Restrictions for browser access

TARGET RESOURCES: Cloud Apps > Office 365 Exchange Online, Office 365 SharePoint Online

CONDITIONS: Client Apps: Browser

ACCESS CONTROLS: Session > Use app enforced restrictions

 

 

NAME: Block access from apps on unmanaged devices (excl iOS and Android)

TARGET RESOURCES: Cloud Apps > Office 365 Exchange Online, Office 365 SharePoint Online

CONDITIONS: Device Platforms > Any Device (excl iOS and Android) | Client Apps > Mobile apps and desktop clients

ACCESS CONTROLS: Grant > Require device to be marked as compliant OR Require Microsoft Entra hybrid joined device

 

Note: we exclude iOS and Android devices as we have these covered by App Protection Policies

 

 

EDIT: Forgot to say, when implementing this I first set the Access Control policy for Unmanaged Devices in the SharePoint Admin Center to Allow limited, web only access (Navigate to SharePoint Admin Center > Policies > Access Control > Unmanaged devices). This then created basic CA policies for me which I then customised to the above.

Edited by gybe78
  • Thanks 3
Posted
How are you stopping it on personal devices but still allowing it for school devices? Can you set this at a group level, as we actively encourage students to use OneDrive sync?
Posted (edited)
How are you stopping it on personal devices but still allowing it for school devices? Can you set this at a group level, as we actively encourage students to use OneDrive sync?

 

I've been testing using @gybe78 advice yesterday, achieving blocking of MS OneDrive (and Outlook) client apps on personal (BYOD) devices - Also found this article that describes the steps.

 

Additionally, been testing App Protection Policies (https://learn.microsoft.com/en-gb/mem/intune/apps/app-protection-policies) again on BYOD (Android/Apple) devices, following this article (https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-framework#level-2-enterprise-enhanced-data-protection) with mostly success. As with all things Intune, policies / settings make take 12/24hrs to apply/update so have to be patient when deciding if the policies are working or they just have not been applied to the device yet!

 

During testing, managed to control the Core Microsoft 365 Apps (though there are more than what are included by default) whilst specifying that the device must be a certain level of OS, password protected, not jail-broken etc. Crucially it does encrypt the data. It does require the downloading and installing the Microsoft Company Portal (however you don't need to log into it or enrol the device). Again, sometimes policies are not apply right away and I am not sure how well, as and when we deploy this, it will work with existing personal/BYOD devices with M365 apps already installed. But it's a step in the right direction.

 

Finally, had quick attempt at 'App Selective Wipe' (https://learn.microsoft.com/en-us/mem/intune/apps/apps-selective-wipe). I did get it to work, albeit many caveats (as always with Intune!) one of which is 'The user must open the app for the wipe to occur, and the wipe may take up to 30 minutes after the request was made'.

Edited by MYK-IT
  • Thanks 1
Posted
I am not sure how well, as and when we deploy this, it will work with existing personal/BYOD devices with M365 apps already installed. But it's a step in the right direction.

 

That's a problem which will naturally solve itself within 3ish years anyway, so it's definitely a goo move in the right direction.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...