Forum Discussion

esnecho991's avatar
esnecho991
Copper Contributor
Sep 08, 2020

Conditional Access control

is it possible to apply conditional access control on a device with one drive app?  if a user is using one drive app and the device is not managed, block downloads. 

6 Replies

  • esnecho991 

    Are the other devices in your environment hybrid azure ad joined? If you have it, you can create a conditional access rule "Block Unmanaged Device File Downloads".

     

    Users and groups: All users

    Cloud App: Office 365 SharePoint Online
    Conditions:
    - Client Apps: Mobile Apps and desktop clients
    - Device state: Configure YES, Include: All device state, Exclude: Device Hybrid Azure AD joined
    Access Controls: Block Access

  • esnecho991 You need to apply app protection policies with condition access to enable DLP in unmanaged devices.

     

    https://docs.microsoft.com/en-us/mem/intune/apps/app-protection-policy

     

Resources