MYK-IT Posted February 7, 2024 Posted February 7, 2024 Hi, I am wondering what other schools do in relation to the OneDrive Client? As in, do you control what devices can install and use the OneDrive client: - School Domain Devices Only - Personal Devices Denied - Personal Device Allowed (/ combined with Condition Access Rules) Whilst there are numerous controls that can be put in place to manage schools devices (e.g. KFM, Files on Demand, SharePoint Resources online only via OneDrive client) all these are not available once using a personal device. Of course, Conditional Access Rules could be used to a degree but ultimately I am thinking of the situation where, most likely a staff member, has synced resources from SharePoint and they are all stored locally on their personal device. One of the biggest issues is the the SharePoint 'Sync' option, which although you can remove this option, by doing so breaks links to those resources using the OneDrive Client (but not online version). https://techcommunity.microsoft.com/t5/sharepoint/want-sharepoint-online-users-to-use-add-shortcut-to-onedrive/m-p/3194536 https://stackoverflow.com/questions/68028076/hide-sync-button-but-allow-add-shortcut-to-onedrive-in-sharepoint-online Thanks,
5tu Posted February 7, 2024 Posted February 7, 2024 Morning We block OneDrive client sync on personal devices and only allow in-browser access to 365 data. It took a while to fine tune our CA rules but I think we've got it covered now. 1
Oaktech Posted February 7, 2024 Posted February 7, 2024 Only available for intune managed devices. Browser access everywhere else, with 2fa.
EssentialRug Posted February 7, 2024 Posted February 7, 2024 Morning We block OneDrive client sync on personal devices and only allow in-browser access to 365 data. It took a while to fine tune our CA rules but I think we've got it covered now. Would you mind sharing your CA policy for this?
5tu Posted February 7, 2024 Posted February 7, 2024 (edited) Would you mind sharing your CA policy for this? Sure. Hope the below makes sense..... NAME: Use app-enforced Restrictions for browser access TARGET RESOURCES: Cloud Apps > Office 365 Exchange Online, Office 365 SharePoint Online CONDITIONS: Client Apps: Browser ACCESS CONTROLS: Session > Use app enforced restrictions NAME: Block access from apps on unmanaged devices (excl iOS and Android) TARGET RESOURCES: Cloud Apps > Office 365 Exchange Online, Office 365 SharePoint Online CONDITIONS: Device Platforms > Any Device (excl iOS and Android) | Client Apps > Mobile apps and desktop clients ACCESS CONTROLS: Grant > Require device to be marked as compliant OR Require Microsoft Entra hybrid joined device Note: we exclude iOS and Android devices as we have these covered by App Protection Policies EDIT: Forgot to say, when implementing this I first set the Access Control policy for Unmanaged Devices in the SharePoint Admin Center to Allow limited, web only access (Navigate to SharePoint Admin Center > Policies > Access Control > Unmanaged devices). This then created basic CA policies for me which I then customised to the above. Edited February 7, 2024 by gybe78 3
MYK-IT Posted February 7, 2024 Author Posted February 7, 2024 Hi @gybe78 Could you expand on your App Protection Policies for IOS and Android? Thanks,
5tu Posted February 7, 2024 Posted February 7, 2024 Hi @gybe78 Could you expand on your App Protection Policies for IOS and Android? Thanks, This is the article I followed when creating them - simple to implement and works really well. 1
thimon Posted February 7, 2024 Posted February 7, 2024 Can use the OneDrive client / app on any device. For staff MFA kicks in on personal devices every 7 days. Looking into MFA for students.
free780 Posted February 7, 2024 Posted February 7, 2024 Or just require Hybrid Joined device for Windows/Mac. App Protection for iOS/Android. CE compliant as well.
enjay Posted February 8, 2024 Posted February 8, 2024 How are you stopping it on personal devices but still allowing it for school devices? Can you set this at a group level, as we actively encourage students to use OneDrive sync?
MYK-IT Posted February 8, 2024 Author Posted February 8, 2024 (edited) How are you stopping it on personal devices but still allowing it for school devices? Can you set this at a group level, as we actively encourage students to use OneDrive sync? I've been testing using @gybe78 advice yesterday, achieving blocking of MS OneDrive (and Outlook) client apps on personal (BYOD) devices - Also found this article that describes the steps. Additionally, been testing App Protection Policies (https://learn.microsoft.com/en-gb/mem/intune/apps/app-protection-policies) again on BYOD (Android/Apple) devices, following this article (https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-framework#level-2-enterprise-enhanced-data-protection) with mostly success. As with all things Intune, policies / settings make take 12/24hrs to apply/update so have to be patient when deciding if the policies are working or they just have not been applied to the device yet! During testing, managed to control the Core Microsoft 365 Apps (though there are more than what are included by default) whilst specifying that the device must be a certain level of OS, password protected, not jail-broken etc. Crucially it does encrypt the data. It does require the downloading and installing the Microsoft Company Portal (however you don't need to log into it or enrol the device). Again, sometimes policies are not apply right away and I am not sure how well, as and when we deploy this, it will work with existing personal/BYOD devices with M365 apps already installed. But it's a step in the right direction. Finally, had quick attempt at 'App Selective Wipe' (https://learn.microsoft.com/en-us/mem/intune/apps/apps-selective-wipe). I did get it to work, albeit many caveats (as always with Intune!) one of which is 'The user must open the app for the wipe to occur, and the wipe may take up to 30 minutes after the request was made'. Edited February 8, 2024 by MYK-IT 1
enjay Posted February 8, 2024 Posted February 8, 2024 I am not sure how well, as and when we deploy this, it will work with existing personal/BYOD devices with M365 apps already installed. But it's a step in the right direction. That's a problem which will naturally solve itself within 3ish years anyway, so it's definitely a goo move in the right direction.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now