SOLVED

CAS Access Control - Restrict users using OneDrive Desktop Client

%3CLINGO-SUB%20id%3D%22lingo-sub-1365972%22%20slang%3D%22en-US%22%3ECAS%20Access%20Control%20-%20Restrict%20users%20using%20OneDrive%20Desktop%20Client%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1365972%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20day!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20created%20an%20Access%20policy%20in%20CAS%20to%20restrict%20the%20access%20to%20OneDrive%20and%20SharePoint%20Client%20only%20not%20including%20Teams%20Client.%20OneDrive%2C%20SharePoint%20and%20Teams%20are%20already%20added%20in%20the%20Conditional%20Access%20App%20Control.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20this%20is%20the%20result%20that%20I%20have%3A%3C%2FP%3E%3CP%3E1.%20Click%20Sync%20Button%20in%20OneDrive%20Online%20----%20Block%20by%20Access%20Control%3C%2FP%3E%3CP%3E2.%20Click%20Sync%20Button%20of%20OneDrive%20in%20Teams%20Online%20----%20Sync%20was%20not%20blocked%3C%2FP%3E%3CP%3E4.%20For%20OneDrive%20that%20is%20already%20syncing%20to%20their%20local%20computer%20the%20files%20are%20still%20syncing.%3C%2FP%3E%3CP%3E5.%20Sign%20to%20Teams%20Client%20----%20Blocked%3C%2FP%3E%3CP%3E6.%20For%20users%20that%20are%20already%20logged-in%20to%20Teams%20Client%20they%20were%20able%20to%20open%20it%20and%20access%20OneDrive%20and%20SharePoint%20FIles%20and%20also%20click%20the%20sync%20button%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuestions%3A%3C%2FP%3E%3CP%3E1.%20How%20to%20restrict%20those%20users%20that%20have%20already%20synced%20their%20OneDrive%20%2F%20SharePoint%3F%3C%2FP%3E%3CP%3E2.%20How%20to%20allow%20Teams%20Client%20and%20block%20the%20sync%20button%3F%3C%2FP%3E%3CP%3E3%2C%20How%20to%20block%20sync%20button%20in%20Teams%20Online%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHoping%20for%20someone's%20help%20here.%20Thank%20you!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1365972%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EData%20Protection%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1385396%22%20slang%3D%22en-US%22%3ERe%3A%20CAS%20Access%20Control%20-%20Restrict%20users%20using%20OneDrive%20Desktop%20Client%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1385396%22%20slang%3D%22en-US%22%3EMCAS%20can%20only%20protect%20web%20workloads%2C%20so%20it%20cannot%20be%20used%20to%20block%20the%20synchronization%20of%20OneDrive%20and%20SharePoint.%20To%20control%20syncing%20you%20need%20to%20configure%20domain%20join%20verification%20inside%20admin.onedrive.com%20and%20that%20will%20apply%20to%20both%20SharePoint%20and%20OneDrive%20sync.%20For%20more%20information%20on%20that%20feature%20read%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fsharepoint-online%2Fset-spotenantsyncclientrestriction%3Fview%3Dsharepoint-ps%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fsharepoint-online%2Fset-spotenantsyncclientrestriction%3Fview%3Dsharepoint-ps%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20cannot%20have%20a%20more%20restrictive%20policy%20for%20SharePoint%20without%20impacting%20Teams%2C%20because%20Teams%20has%20a%20dependency%20on%20SharePoint.%20For%20more%20information%20on%20the%20dependent%20services%20and%20how%20you%20can't%20have%20separate%20restrictions%2C%20view%20this%20article%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Fservice-dependencies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Fservice-dependencies%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20block%20sync%20in%20Teams%20you%20have%20to%20disable%20it%20in%20the%20library%20settings%20as%20described%20here%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fanswers.microsoft.com%2Fen-us%2Fmsoffice%2Fforum%2Fall%2Fdisable-sync-options-on-office-365-group-team-site%2F87180381-f0fc-411b-9895-8b3ee5df0dde%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fanswers.microsoft.com%2Fen-us%2Fmsoffice%2Fforum%2Fall%2Fdisable-sync-options-on-office-365-group-team-site%2F87180381-f0fc-411b-9895-8b3ee5df0dde%3C%2FA%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Good day!

 

I created an Access policy in CAS to restrict the access to OneDrive and SharePoint Client only not including Teams Client. OneDrive, SharePoint and Teams are already added in the Conditional Access App Control. 

 

And this is the result that I have:

1. Click Sync Button in OneDrive Online ---- Block by Access Control

2. Click Sync Button of OneDrive in Teams Online ---- Sync was not blocked

4. For OneDrive that is already syncing to their local computer the files are still syncing.

5. Sign to Teams Client ---- Blocked

6. For users that are already logged-in to Teams Client they were able to open it and access OneDrive and SharePoint FIles and also click the sync button

 

Questions:

1. How to restrict those users that have already synced their OneDrive / SharePoint?

2. How to allow Teams Client and block the sync button?

3, How to block sync button in Teams Online?

 

Hoping for someone's help here. Thank you!

1 Reply
Highlighted
Best Response confirmed by Mary_Yvette (Contributor)
Solution
MCAS can only protect web workloads, so it cannot be used to block the synchronization of OneDrive and SharePoint. To control syncing you need to configure domain join verification inside admin.onedrive.com and that will apply to both SharePoint and OneDrive sync. For more information on that feature read here: https://docs.microsoft.com/en-us/powershell/module/sharepoint-online/set-spotenantsyncclientrestrict...

You cannot have a more restrictive policy for SharePoint without impacting Teams, because Teams has a dependency on SharePoint. For more information on the dependent services and how you can't have separate restrictions, view this article here: https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/service-dependencies

To block sync in Teams you have to disable it in the library settings as described here:
https://answers.microsoft.com/en-us/msoffice/forum/all/disable-sync-options-on-office-365-group-team...