Forum Discussion
krishnasembee
Jul 15, 2021Copper Contributor
Block upload of documents to other office 365 tenant
I wish to block upload of documents to Other Office 365 tenant on a managed device? Can this be achieved using MCAS
MZyarah
Jul 30, 2021Brass Contributor
As I know tenant restrictions not applied beyond corporate network perimeter or maybe it can be done with special criteria.
About the Encryption, for me I like to Encrypt the data everywhere however the main question was the MCAS is able to fix this issue!
In the question which not clear enough, I don't think the encryption will solve the requirements.
Let's consider this scenario, you have access for two tenants, one of them provided you with a managed device " mentioned in the main question also".
Now you have Managed Device and access to data in Tenant1 and Only access to data in tenant2 (you can consider the data is encrypted at rest and in transit if you like)
for example, what will prevent the user from opening a web session and browse to the tenant2 OneDrive and copy data from the local/tenant1 data to the second one?
If the encryption help, can you refer me to a doc/blog explaining same thing please.
About the Encryption, for me I like to Encrypt the data everywhere however the main question was the MCAS is able to fix this issue!
In the question which not clear enough, I don't think the encryption will solve the requirements.
Let's consider this scenario, you have access for two tenants, one of them provided you with a managed device " mentioned in the main question also".
Now you have Managed Device and access to data in Tenant1 and Only access to data in tenant2 (you can consider the data is encrypted at rest and in transit if you like)
for example, what will prevent the user from opening a web session and browse to the tenant2 OneDrive and copy data from the local/tenant1 data to the second one?
If the encryption help, can you refer me to a doc/blog explaining same thing please.
Darren_Bennett
Aug 01, 2021Copper Contributor
In that scenario, you use a conditional access policy that states the device must be compliant to authenticate. The user would need a device for each tenant.
Again this now fixes this one very specific issue.
I think we need clearer definition of what the intended outcomes are. I agree, there are many scenarios, without knowing more, I don't believe we can provide an answer.
Again this now fixes this one very specific issue.
I think we need clearer definition of what the intended outcomes are. I agree, there are many scenarios, without knowing more, I don't believe we can provide an answer.