Forum Discussion
Rob Giesen
Apr 04, 2017Copper Contributor
Is it possible to limit acces to a SharePoint online site to a list of know devices?
Hi there,
As said in the title, Is it possible to limit acces to a SharePoint online site to a list of know devices?
We make use of the Surface Pro 4 devices in our office and we only whant that those devices have acces to a particular site.
We also have other sites that can (this must not change) be accesed without this device, just by going to an URL.
Hope to get some input!
Regards,
Rob
Hi,
Since a few months we have Conditional Access Policies
As the article describes Device-based conditional access policies require the use Intune and AAD-premium. The policy is applied to the entire tenant as far as I understand so it seems you can't apply it to certain sites
Hope this helps
6 Replies
Sort By
- Dean_GrossSilver Contributor
I'm curious, what is the business scenario that requires a specific site to only be accessible to specific type of device?
- Rob GiesenCopper Contributor
Its a bit hard to explain, but i will try :).
We sell devices with a custom on premise application, that connects to a O365 SharePoint site.
We want to limit the login to those sites to only those devices, that they cannot go to the site on any other devices that the ones we sell.
This because of the data on thos site, its very confidential.
- Dean_GrossSilver Contributor
I don't think that what you want to do is possible. I would recommend focusing on implementing a strategy that focuses on using the identity of the users. This is the control plane that MS has invested a very large amount of resources and should provide you the necessary level of control.
- paulpaschaBronze Contributor
Hi,
Since a few months we have Conditional Access Policies
As the article describes Device-based conditional access policies require the use Intune and AAD-premium. The policy is applied to the entire tenant as far as I understand so it seems you can't apply it to certain sites
Hope this helps
- Rob GiesenCopper Contributor
Thank you this is an option, not the best fitting for us (due the fact it also blocks Onedrive and SharePoint Online for users that arent on the IP list) but a valid option never the less :)