enjay Posted May 20 Posted May 20 For safeguarding reasons, we'd like to prevent students from being able to access documents shared with them by people outside the organisation. I've done this with Google Workspace, but not been able to fully do it with M365. If you select to share the document with the student by name, it doesn't work but if you share a document "to anyone with the link", students can still access them. Does anyone know a way of stopping this, without impacting students' ability to access their school M365 account? I've noticed their school OneDrive address is https://schoolname-my.sharepoint.com/shared but a personal OneDrive begins https://onedrive.live.com/:w:/g/personal, so could I just block the onedrive.live.com domain, or would that prevent students logging in to their school account too?
NicholasEsping Posted May 20 Posted May 20 57 minutes ago, enjay said: For safeguarding reasons, we'd like to prevent students from being able to access documents shared with them by people outside the organisation. I've done this with Google Workspace, but not been able to fully do it with M365. If you select to share the document with the student by name, it doesn't work but if you share a document "to anyone with the link", students can still access them. Does anyone know a way of stopping this, without impacting students' ability to access their school M365 account? I've noticed their school OneDrive address is https://schoolname-my.sharepoint.com/shared but a personal OneDrive begins https://onedrive.live.com/:w:/g/personal, so could I just block the onedrive.live.com domain, or would that prevent students logging in to their school account too? Depending on how your web filter works you could block sharepoint.com and onedrive.live.com and then add a allow rule that allows https://schoolname-my.sharepoint.com.
enjay Posted May 20 Author Posted May 20 1 minute ago, NicholasEsping said: Depending on how your web filter works you could block sharepoint.com and onedrive.live.com and then add a allow rule that allows https://schoolname-my.sharepoint.com. I could do that but I am not sure if the M365 login process uses something at live.com, in the same way some logins to Google Drive go via a YouTube URL. I wonder if my filters can block the string https://onedrive.live.com/:w:/g/personal but not the overall domain...
sigma Posted May 20 Posted May 20 1 hour ago, enjay said: For safeguarding reasons, we'd like to prevent students from being able to access documents shared with them by people outside the organisation. I've done this with Google Workspace, but not been able to fully do it with M365. If you select to share the document with the student by name, it doesn't work but if you share a document "to anyone with the link", students can still access them. Does anyone know a way of stopping this, without impacting students' ability to access their school M365 account? I've noticed their school OneDrive address is https://schoolname-my.sharepoint.com/shared but a personal OneDrive begins https://onedrive.live.com/:w:/g/personal, so could I just block the onedrive.live.com domain, or would that prevent students logging in to their school account too? I block onedrive.live.com to prevent pupils accessing their personal Onedrive at school - and just allow school ones. I currenty do it with Impero rather than Filtering at the moment.
enjay Posted May 21 Author Posted May 21 20 hours ago, sigma said: I block onedrive.live.com to prevent pupils accessing their personal Onedrive at school - and just allow school ones. Thanks. We've also blocked things like DropBox for students for similar reasons. Google Drive continues to present a challenge, as I'm not sure of a way to stop students accessing personal Drives while still allowing access to the school one. Why students are still using Google when we moved to Microsoft 5+ years ago is another topic!
dmj Posted May 21 Posted May 21 22 hours ago, enjay said: For safeguarding reasons, we'd like to prevent students from being able to access documents shared with them by people outside the organisation. I've done this with Google Workspace, but not been able to fully do it with M365. If you select to share the document with the student by name, it doesn't work but if you share a document "to anyone with the link", students can still access them. Does anyone know a way of stopping this, without impacting students' ability to access their school M365 account? Doesn't the content filter determine if they are safe?
sigma Posted May 21 Posted May 21 12 minutes ago, dmj said: Doesn't the content filter determine if they are safe? Nope. The content filter doesn't (can't?) tell if its your onedrive or somebody elses, and "generally" has no idea if it's safe or not.
enjay Posted May 21 Author Posted May 21 29 minutes ago, dmj said: Doesn't the content filter determine if they are safe? Not really, no. It might flag certain inappropriate words but you can do/say a lot without using those words, and it wouldn't block images which had been inserted into a Google Doc, for example.
tom_newton Posted May 21 Posted May 21 You can find the odd content filter that's capable of looking in both words, and images i google docs. If your current filter supports regex, you might be able to find a regex to match document share URLs for 365 1
dmj Posted May 21 Posted May 21 58 minutes ago, sigma said: Nope. The content filter doesn't (can't?) tell if its your onedrive or somebody elses, and "generally" has no idea if it's safe or not. 55 minutes ago, enjay said: Not really, no. It might flag certain inappropriate words but you can do/say a lot without using those words, and it wouldn't block images which had been inserted into a Google Doc, for example. I does seem like this is literally what content filters are for, i.e. scanning websites for bad content and blocking based on said content. I guess the internet has come along a bit since I last had to deal with this stuff, and perhaps content filters haven't kept pace.
enjay Posted May 21 Author Posted May 21 5 minutes ago, dmj said: I does seem like this is literally what content filters are for, i.e. scanning websites for bad content and blocking based on said content. I guess the internet has come along a bit since I last had to deal with this stuff, and perhaps content filters haven't kept pace. Blocking text and blocking images are very different things. Also I think the complexity of live-sharing a document and the speed with which text can be typed and deleted adds a challenge which content filters didn't previously have to contend with. 1
dmj Posted May 21 Posted May 21 1 hour ago, enjay said: Blocking text and blocking images are very different things. Also I think the complexity of live-sharing a document and the speed with which text can be typed and deleted adds a challenge which content filters didn't previously have to contend with. Shame. At the beginning (of using the internet in schools) we started by allowlisting sites, then dynamic filtering came along. Now we seem to be back where we started. Progress I guess. 1
sigma Posted May 21 Posted May 21 For sites.google.com and docs.google.com I do operate an allow list for pupils as there are so many lists of proxy sites and other unsafe things there. We are not a Google school (apart from the staff shadow IT system), so its not a big deal.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now