Home

Can you restrict downloading from Teams?

%3CLINGO-SUB%20id%3D%22lingo-sub-274466%22%20slang%3D%22en-US%22%3ECan%20you%20restrict%20downloading%20from%20Teams%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-274466%22%20slang%3D%22en-US%22%3E%3CP%3EI%20would%20like%20to%20create%20a%20'Any%20device%2C%20anywhere'%20conditional%20access%20policy%20where%20by%20if%20you%20are%20using%20a%20corporate%20domain%20joined%20computer%20it%20will%20let%20you%20access%20and%20download%20o365%20files%20BUT%20if%20you%20are%20on%20a%20personal%20device%20e.g.%20home%20computer%20or%20public%20computer%20it%20will%20restrict%20downloads.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20created%20the%20policies%20needed%20using%20the%20%5BSharePoint%20Admin%20center%5D%20conditional%20access%20polices%20in%20Intune%20and%20initially%20I%20thought%20they%20worked%20great.%26nbsp%3B%20If%20I%20was%20on%20public%20computer%20it%20allowed%20me%20to%20access%20and%20edit%20OneDrive%20and%20SharePoint%20files%20within%20the%20web%20browser%20and%20if%20I%20tried%20to%20download%20them%20locally%20it%20wouldn't%20let%20me!%20Great!%26nbsp%3B%20However%2C%20I've%20spotted%20a%20loophole.%26nbsp%3B%20You%20can%20get%20around%20this%20by%20opening%20these%20files%20through%20Teams%20as%20the%20conditional%20access%20policy%20doesn't%20seem%20to%20apply%20to%20Microsoft%20Teams!%26nbsp%3B%20Anyone%20else%20spotted%20this%20or%20know%20a%20workaround%20or%20fix%20for%20this%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-274466%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-274477%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20restrict%20downloading%20from%20Teams%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-274477%22%20slang%3D%22en-US%22%3ENot%20sure%20if%20you%20can%20get%20Teams%20to%20work%2C%20however%20if%20it%20works%20with%20SharePoint%20it%20will%20work%20in%20Teams%20soon%20when%20they%20replace%20the%20Files%20tab%20with%20SharePoint%20Modern%20Library%20UI.%20So%20it%20might%20be%20a%20matter%20of%20waiting%20for%20that%20release.%20No%20idea%20when%20that%20is%20coming%20but%20it%20should%20be%20by%20year%20end%20worse%20case%2C%20but%20it%20could%20be%20any%20week.%3CBR%20%2F%3E%3CBR%20%2F%3EGo%20to%20Teams%20files%20tab%2C%20and%20click%20%22Open%20in%20SharePoint%22%2C%20then%20try%20to%20see%20if%20it%20works%20from%20the%20attached%20Team%20SharePoint%20site.%20If%20it%20does%2C%20then%20the%20files%20tab%20release%20should%20fix%20your%20issue.%20Otherwise%20if%20it%20doesn't%2C%20then%20your%20settings%20aren't%20applying%20to%20the%20underlying%20SharePoint%20site%20the%20teams%20are%20attached%20to%20and%20I%20would%20check%20there!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-993625%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20restrict%20downloading%20from%20Teams%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-993625%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20been%20digging%20through%20CA%20and%20Intune%20policies%2C%20still%20no%20luck%20on%20this%20one.%26nbsp%3B%20Am%20I%20missing%20something%20simple%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-994598%22%20slang%3D%22en-US%22%3ERE%3A%20Can%20you%20restrict%20downloading%20from%20Teams%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-994598%22%20slang%3D%22en-US%22%3Ethis%20works%20for%20me%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Fcontrol-access-from-unmanaged-devices%3FredirectSourcePath%3D%25252fen-us%25252farticle%25252fcontrol-access-from-unmanaged-devices-5ae550c4-bd20-4257-847b-5c20fb053622%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Fcontrol-access-from-unmanaged-devices%3FredirectSourcePath%3D%25252fen-us%25252farticle%25252fcontrol-access-from-unmanaged-devices-5ae550c4-bd20-4257-847b-5c20fb053622%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-994785%22%20slang%3D%22en-US%22%3ERE%3A%20Can%20you%20restrict%20downloading%20from%20Teams%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-994785%22%20slang%3D%22en-US%22%3E%3CP%3Ethis%20works%20for%20me%3A%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F439273%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Fcontrol-access-from-unmanaged-devices%3FredirectSourcePath%3D%25252fen-us%25252farticle%25252fcontrol-access-from-unmanaged-devices-5ae550c4-bd20-4257-847b-5c20fb053622%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-996651%22%20slang%3D%22en-US%22%3ERE%3A%20Can%20you%20restrict%20downloading%20from%20Teams%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-996651%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F13364%22%20target%3D%22_blank%22%3E%40David%20Phillips%3C%2FA%3E%26nbsp%3Bno%20it%20doesn't%20allow%20users%20using%20Team%20client%20anymore.%20you%20can%20chose%20between%20no%20acces%20or%20only%20Webaccess%20from%20unmanaged%20devices...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eif%20you%20would%20like%20to%20use%20teams%20client%20I%20think%20than%20you%20need%20to%20use%20CA%20and%20Cloud%20APP%20Security%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Fuse-case-proxy-block-session-aad%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Fuse-case-proxy-block-session-aad%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Chris Brooks
Senior Member

I would like to create a 'Any device, anywhere' conditional access policy where by if you are using a corporate domain joined computer it will let you access and download o365 files BUT if you are on a personal device e.g. home computer or public computer it will restrict downloads.  

 

I've created the policies needed using the [SharePoint Admin center] conditional access polices in Intune and initially I thought they worked great.  If I was on public computer it allowed me to access and edit OneDrive and SharePoint files within the web browser and if I tried to download them locally it wouldn't let me! Great!  However, I've spotted a loophole.  You can get around this by opening these files through Teams as the conditional access policy doesn't seem to apply to Microsoft Teams!  Anyone else spotted this or know a workaround or fix for this? 

5 Replies
Not sure if you can get Teams to work, however if it works with SharePoint it will work in Teams soon when they replace the Files tab with SharePoint Modern Library UI. So it might be a matter of waiting for that release. No idea when that is coming but it should be by year end worse case, but it could be any week.

Go to Teams files tab, and click "Open in SharePoint", then try to see if it works from the attached Team SharePoint site. If it does, then the files tab release should fix your issue. Otherwise if it doesn't, then your settings aren't applying to the underlying SharePoint site the teams are attached to and I would check there!

I've been digging through CA and Intune policies, still no luck on this one.  Am I missing something simple?

@Tommek Does that allow your users to launch the Teams client on an unmanaged devices, but prevent them from using Teams to download files from SPO / OneDrive?  I'm not seeing that behavior here.

@David Phillips no it doesn't allow users using Team client anymore. you can chose between no acces or only Webaccess from unmanaged devices...

 

if you would like to use teams client I think than you need to use CA and Cloud APP Security https://docs.microsoft.com/en-us/cloud-app-security/use-case-proxy-block-session-aad

 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies