View-only but not download docs in Teams

%3CLINGO-SUB%20id%3D%22lingo-sub-285664%22%20slang%3D%22en-US%22%3EView-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-285664%22%20slang%3D%22en-US%22%3EWe%20have%20an%20executive%20user%20who%20wishes%20to%20share%20a%20sensitive%20document%20with%20a%20few%20key%20external%20stakeholders%2C%20but%20her%20boss%20won't%20let%20her%20do%20it%20if%20the%20file%20can%20be%20downloaded.%20She's%20requesting%20we%20provide%20a%20view-only%20permission%2C%20that%20enables%20viewing%20and%20reading%20the%20file%20online%2C%20without%20enabling%20end%20users%20to%20download%20the%20file.%20Now%2C%20if%20we%20disregard%20all%20of%20the%20potential%20loopholes%20and%20workarounds%20that%20might%20render%20this%20permission%20ineffective...%20is%20this%20even%20possible%3F%20I%20think%20it%20was%20historically%20possible%20to%20accomplish%20this%20in%20SharePoint%20permissions%20but%20it%20doesn't%20appear%20to%20be%20available%20in%20SharePoint%20Online%3F%20Can%20anyone%20point%20me%20in%20the%20right%20direction%20to%20answer%20this%20question%20definitively%3F%20and%20if%20it%20IS%20possible%2C%20to%20a%20resource%3F%20My%20searching%20has%20not%20found%20anything%20recent%20that%20answers%20this%20question.%20Thanks!%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-285664%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EFiles%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EGuest%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-288518%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-288518%22%20slang%3D%22en-US%22%3E%3CP%3EBoth%20sides%20have%20merit%20and%20I%20get%20where%20you%20are%20coming%20from%20Steven%2C%20however%20I%20agree%20with%20Tony%20on%20this%20one.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETrading%20off%20the%20ease%20of%20use%20of%20loading%20a%20doc%20in%20the%20web%20browser%20versus%20the%20enhanced%20lock%20down%20security%20of%20AIP%20(with%20some%20extra%20steps)%2C%20I'd%20be%20going%20with%20that.%20But%20then%20again%20each%20to%20their%20own%20based%20on%20ones%20needs!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20loving%20this%26nbsp%3Bintellectual%20discussion%20of%20ideas%20and%20philosophies%20on%20security%20but%20I%20will%20also%20say%20to%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F95396%22%20target%3D%22_blank%22%3E%40Rinch%20Anderson%3C%2FA%3E%20to%20please%20accept%20our%20apologies%20for%20hijacking%20your%20question.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20AIP%20discussion%20is%20the%20next%20evolution%20of%20digital%20security%20(takes%20it%20to%20a%20whole%20new%20level)%20that%20you%20may%20want%20to%20consider%20in%20the%20future%2C%20but%20it%20isn't%20related%20to%20your%20SharePoint%20question%20about%20preventing%20users%20from%20downloading%20a%20file!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHopefully%20though%20the%20info%20helps%20in%20some%20future%20planning.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%3C%2FP%3E%3CP%3EDamien%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-288125%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-288125%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20user%20experience%20around%20protected%20documents%20stored%20in%20SharePoint%20could%20be%20considerably%20enhanced.%20It's%20kind%20of%20stuck%20around%202000%20whereas%20the%20protection%20of%20email%20has%20moved%20forward%20quite%20nicely.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EEven%20so%2C%20I%20think%20there%20is%20value%20in%20protecting%20really%20confidential%20documents%20with%20rights%20management.%20Sure%2C%20the%20preview%20won't%20work%20(along%20with%20other%20issues%20like%20no%20co-authoring%20and%20an%20inability%20to%20search%20for%20protected%20content)%2C%20but%20if%20it%20is%20confidential%20material%20I%20think%20people%20understand%20that%20they%20have%20to%20go%20through%20a%20process%20to%20access%20it.%20After%20all%2C%20if%20you%20receive%20confidential%20information%20in%20the%20mail%2C%20you%20likely%20have%20to%20sign%20for%20the%20letter%20and%20then%20open%20a%20much%20more%20protected%20envelope%20than%20the%20norm.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-288110%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-288110%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F89704%22%20target%3D%22_blank%22%3E%40Damien%20Rosario%3C%2FA%3E%20yes%20AIP%20has%20those%20features%2C%20but%20it%20currently%20also%20has%20the%20downsides%20I%20discussed.%20Using%20an%20AIP%20protected%20document%20through%20Teams%20is%20a%20significantly%20compromised%20experience%20where%20you%20need%20to%20open%20in%20Word%2FExcel%2FPpt%20just%20to%20view.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20think%20blocking%20copy%20etc%20isn't%20really%20a%20control%2C%20a%20user%20can%20still%20take%20a%20photo%20of%20the%20screen%2C%20you%20are%20just%20making%20it%20more%20fiddly.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-287436%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-287436%22%20slang%3D%22en-US%22%3E%3CDIV%3E%3CFONT%3EHi%20Steven%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CFONT%3EWould%26nbsp%3Byour%20suggestion%20prevent%20the%20recipient%20from%20using%20copy%2Fpaste%20and%20screen%20grab%20of%20the%20document%20content%20too%3F%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CFONT%3EFrom%20a%20security%20standpoint%2C%20that%20would%20be%20a%20big%20one%20I%20would%20think.%26nbsp%3B%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CFONT%3EAs%20you%20know%2C%20AIP%20gives%20us%20full%20access%20to%20control%20the%20document%20at%20anytime%20and%20stops%20screen%20grabs%2C%20copy%2Fpate%2C%20etc%2C%20which%20is%20powerful%20stuff.%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CFONT%3ECheers%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%3CFONT%3EDamien%3C%2FFONT%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-287341%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-287341%22%20slang%3D%22en-US%22%3E%3CP%3E-1%20for%20AIP%20policies%2C%20it%20kind%20of%20does%20the%20opposite%20of%20what's%20being%20requested%20in%20that%20it%20would%20force%20everyone%20to%20download%20the%20file%20in%20order%20to%20view%20it.%20Yes%20it's%20secure%20and%20protected%20when%20downloaded%2C%20but%20the%20user%20inconvenience%20of%20not%20being%20able%20to%20view%20online%2C%20co-edit%20or%20be%20searched%20for%20is%20pretty%20significant.%20If%20you%20are%20also%20assuming%20that%20it%20will%20just%20work%20for%20external%20guests%20who%20could%20have%20all%20sorts%20of%20different%20versions%20of%20Office%20you%20can%20expect%20a%20bumpy%20ride.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20prevent%20download%20from%20SharePoint%20using%20site-scoped%20conditional%20access%2C%20that%20way%20you%20would%20retain%20all%20the%20behaviour%20but%20be%20unable%20to%20download.%20See%26nbsp%3B%3CFONT%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Active-Directory-Identity%2FConditional-Access-8220-limited-access-8221-policies-for%2Fba-p%2F245228%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Active-Directory-Identity%2FConditional-Access-8220-limited-access-8221-policies-for%2Fba-p%2F245228%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-287332%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-287332%22%20slang%3D%22en-US%22%3E%3CP%3EWith%20the%20new%20sensitivity%20labels%20functionality%20available%20in%20Office%20365%2C%20you%20can%20create%20a%20new%20label%20with%20encryption%2C%20assign%20the%20rights%20to%20the%20external%20people%20you%20want%20to%20have%20access%20to%20read%20(but%20maybe%20not%20print%20or%20copy)%20the%20document%2C%20and%20put%20the%20document%20in%20the%20SharePoint%20library%20owned%20by%20the%20team.%20It's%20a%20variant%20of%20what%20I%20discuss%20in%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.petri.com%2Fprotecting-office-365-document-libraries-guest-users%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petri.com%2Fprotecting-office-365-document-libraries-guest-users%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20need%20more%20information%20about%20sensitivity%20labels%2C%20they're%20available%20online%20or%20in%20the%20Office%20365%20for%20IT%20Pros%20eBook%20(Chapter%2024).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-285857%22%20slang%3D%22en-US%22%3ERE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-285857%22%20slang%3D%22en-US%22%3E%2B1%20for%20AIP%20and%20Compliance%20features%20in%20Office%20365%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-285744%22%20slang%3D%22en-US%22%3ERe%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-285744%22%20slang%3D%22en-US%22%3E%2B1%20for%20AIP%20and%20Compliance%20features%20in%20Office%20365%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-285736%22%20slang%3D%22en-US%22%3ERe%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-285736%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F95396%22%20target%3D%22_blank%22%3E%40Rinch%20Anderson%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20agree%20with%20Adam%20that%20Azure%20Information%20Protection%20(AIP)%20is%20the%20way%20to%20go%20as%20you%20can%20revoke%20permissions%20to%20the%20file%20at%20any%20time%2C%20as%20well%20as%20see%20where%20in%20the%20world%20the%20file%20has%20been%20opened%2C%20etc.%20It's%20very%20powerful!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20OneDrive%2FSharePoint%20solution%20mentioned%20sounds%20good%20too%20but%20no%20solution%20is%20fool%20proof%20as%20people%20can%20take%20a%20photo%20with%20their%20camera%2C%20etc%20as%20a%20work%20around%20(out%20of%20any%20software%20vendors%20control).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%26nbsp%3Bpointing%20this%20out%20for%20your%20awareness.%20You%20may%20also%20want%20to%20include%20a%20disclaimer%20about%20privacy%2Fconfidentiality%20that%20users%20accept%20when%20opening%20the%20file.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20wishes!%3C%2FP%3E%3CP%3EDamien%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-285729%22%20slang%3D%22en-US%22%3ERe%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-285729%22%20slang%3D%22en-US%22%3EHi!%20Currently%20this%20is%20only%20possible%20with%20IRM%20right%20now%20(%20azure%20rms%20)%20but%20it%20seems%20this%20feature%20is%20coming%20to%20onedrive%20natively%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fonedrive.uservoice.com%2Fforums%2F913531-onedrive-sharing-collaboration%2Fsuggestions%2F7105024-prevent-shared-files-from-being-downloaded%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fonedrive.uservoice.com%2Fforums%2F913531-onedrive-sharing-collaboration%2Fsuggestions%2F7105024-prevent-shared-files-from-being-downloaded%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1985905%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1985905%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F178440%22%20target%3D%22_blank%22%3E%40Steven%20Collier%3C%2FA%3E%26nbsp%3B%2C%20I%20tried%20this%20limited%20access%20setting%20for%20SharePoint%20once%20and%20it%20broke%20all%20our%20MAM-only%20Mobile%20devices'%20access%20to%20OneDrive.%26nbsp%3B%20Started%20prompting%20users%20to%20enroll%20in%20Intune%20if%20they%20wanted%20to%20be%20able%20to%20access%20their%20OneDrive%20files.%26nbsp%3B%20Needless%20to%20say%20I%20had%20to%20roll%20back%20the%20change%20and%20re-activate%20a%20bunch%20of%20mobile%20devices%20for%20MAM-only.%26nbsp%3B%20At%20the%20time%20Microsoft%20was%20as%20surprised%20as%20I%20was%20(this%20was%20about%203%20years%20ago)%20and%20said%20they%20would%20try%20to%20fix%20this%20cross-over%20issue%20between%20personal%20computers%20and%20personal%20devices%2C%20but%20from%20the%20article%20you%20linked%20it%20appears%20they%20are%20treating%20it%20as%20a%20feature%20now%20and%20not%20a%20bug%20so%20I%20assume%20this%20is%20never%20going%20to%20change%20now.%20This%20is%20disappointing%20for%20those%20of%20us%20that%20get%20all%20the%20security%20we%20need%20from%20Application%20Protection%20policies%20(MAM)%20and%20don't%20need%20the%20extra%20aggro%20of%20device%20enrollment%2C%20but%20still%20would%20like%20to%20allow%20limited%20SharePoint%20access%20on%20users'%20personal%20computers.%26nbsp%3B%20%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1986133%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1986133%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F92409%22%20target%3D%22_blank%22%3E%40Derek%20Pickell%3C%2FA%3E%2C%20this%20is%20a%20very%20old%20thread%20from%20over%202%20years%20ago%2C%20the%20options%20are%20very%20different%20now.%26nbsp%3B%20MIP%20has%20largely%20replaced%20AIP%20and%20is%20now%20available%20in%20the%20browser.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1986470%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1986470%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F178440%22%20target%3D%22_blank%22%3E%40Steven%20Collier%3C%2FA%3E%26nbsp%3B%2C%20yes%20sorry%20I%20was%20venting%20my%20spleen%20on%20this%20thread%20because%20my%20boss%20recently%20asked%20me%20why%20we%20can't%20enable%20limited%20SharePoint%20access%20on%20personal%20computers%20for%20our%20staff%20and%20I%20was%20disappointed%20to%20find%20that%20even%20after%20all%20this%20time%20this%20option%20would%20still%20break%20our%20mobile%20MAM-only%20solution.%26nbsp%3B%20Microsoft%20has%20just%20called%20it%20out%20(device%20enrollment)%20as%20an%20additional%20security%20feature%20so%20we%20have%20no%20choice%20but%20to%20implement%20it%20if%20we%20want%20limited%20SharePoint%20access.%26nbsp%3B%20It%20rankles%20because%20the%20way%20we%20have%20MAM%20policies%20currently%20configured%20is%20sufficient%20to%20prevent%20data%20exfiltration.%26nbsp%3B%20Device%20Enrollment%2C%20while%20preferred%20by%20me%20as%20an%20Admin%2C%20is%20not%20preferred%20by%20the%20thousands%20of%20personal%20device%20users%20we%20have%20on%20staff.%26nbsp%3B%20I%20now%20have%20to%20explain%20to%20my%20management%20that%20we%20have%20to%20choose%20between%20mobile%20device%20enrollment%20and%20limited%20sharepoint%20access.%26nbsp%3B%20We%20have%20DLP%20projects%20working%20on%20MIP%20but%20that%20won't%20%3CEM%3Eprevent%3C%2FEM%3E%20data%20downloads%20to%20personal%20devices%20which%20is%20what%20they%20are%20most%20concerned%20with.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1986794%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20View-only%20but%20not%20download%20docs%20in%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1986794%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F92409%22%20target%3D%22_blank%22%3E%40Derek%20Pickell%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI'm%20not%20really%20an%20expert%20in%20that%20area%2C%20but%20the%20SharePoint%20restrictions%20trigger%20Conditional%20Access%20policies%2C%20is%20it%20not%20possible%20to%20change%20the%20conditions%20on%20the%20policy%20to%20exclude%20iOS%20and%20Android%20but%20keep%20blocking%20Windows%20and%20MAC.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ELike%20this%20...%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Screenshot%202020-12-14%20205801.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F240393i308EBA9ACE710605%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Screenshot%202020-12-14%20205801.png%22%20alt%3D%22Screenshot%202020-12-14%20205801.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Senior Member
We have an executive user who wishes to share a sensitive document with a few key external stakeholders, but her boss won't let her do it if the file can be downloaded. She's requesting we provide a view-only permission, that enables viewing and reading the file online, without enabling end users to download the file. Now, if we disregard all of the potential loopholes and workarounds that might render this permission ineffective... is this even possible? I think it was historically possible to accomplish this in SharePoint permissions but it doesn't appear to be available in SharePoint Online? Can anyone point me in the right direction to answer this question definitively? and if it IS possible, to a resource? My searching has not found anything recent that answers this question. Thanks!
14 Replies
Hi! Currently this is only possible with IRM right now ( azure rms ) but it seems this feature is coming to onedrive natively:

https://onedrive.uservoice.com/forums/913531-onedrive-sharing-collaboration/suggestions/7105024-prev...

Hi @Rinch Anderson

 

I agree with Adam that Azure Information Protection (AIP) is the way to go as you can revoke permissions to the file at any time, as well as see where in the world the file has been opened, etc. It's very powerful!

 

The OneDrive/SharePoint solution mentioned sounds good too but no solution is fool proof as people can take a photo with their camera, etc as a work around (out of any software vendors control).

 

Just pointing this out for your awareness. You may also want to include a disclaimer about privacy/confidentiality that users accept when opening the file.

 

Best wishes!

Damien

+1 for AIP and Compliance features in Office 365
+1 for AIP and Compliance features in Office 365

With the new sensitivity labels functionality available in Office 365, you can create a new label with encryption, assign the rights to the external people you want to have access to read (but maybe not print or copy) the document, and put the document in the SharePoint library owned by the team. It's a variant of what I discuss in https://www.petri.com/protecting-office-365-document-libraries-guest-users 

 

If you need more information about sensitivity labels, they're available online or in the Office 365 for IT Pros eBook (Chapter 24).

-1 for AIP policies, it kind of does the opposite of what's being requested in that it would force everyone to download the file in order to view it. Yes it's secure and protected when downloaded, but the user inconvenience of not being able to view online, co-edit or be searched for is pretty significant. If you are also assuming that it will just work for external guests who could have all sorts of different versions of Office you can expect a bumpy ride.

 

You can prevent download from SharePoint using site-scoped conditional access, that way you would retain all the behaviour but be unable to download. See https://techcommunity.microsoft.com/t5/Azure-Active-Directory-Identity/Conditional-Access-8220-limit...

Hi Steven
 
Would your suggestion prevent the recipient from using copy/paste and screen grab of the document content too?
 
From a security standpoint, that would be a big one I would think. 
 
As you know, AIP gives us full access to control the document at anytime and stops screen grabs, copy/pate, etc, which is powerful stuff.
 
Cheers
Damien

@Damien Rosario yes AIP has those features, but it currently also has the downsides I discussed. Using an AIP protected document through Teams is a significantly compromised experience where you need to open in Word/Excel/Ppt just to view.

 

I think blocking copy etc isn't really a control, a user can still take a photo of the screen, you are just making it more fiddly.

 

 

The user experience around protected documents stored in SharePoint could be considerably enhanced. It's kind of stuck around 2000 whereas the protection of email has moved forward quite nicely.

 

Even so, I think there is value in protecting really confidential documents with rights management. Sure, the preview won't work (along with other issues like no co-authoring and an inability to search for protected content), but if it is confidential material I think people understand that they have to go through a process to access it. After all, if you receive confidential information in the mail, you likely have to sign for the letter and then open a much more protected envelope than the norm.

Both sides have merit and I get where you are coming from Steven, however I agree with Tony on this one.

 

Trading off the ease of use of loading a doc in the web browser versus the enhanced lock down security of AIP (with some extra steps), I'd be going with that. But then again each to their own based on ones needs!

 

I am loving this intellectual discussion of ideas and philosophies on security but I will also say to @Rinch Anderson to please accept our apologies for hijacking your question.

 

The AIP discussion is the next evolution of digital security (takes it to a whole new level) that you may want to consider in the future, but it isn't related to your SharePoint question about preventing users from downloading a file!

 

Hopefully though the info helps in some future planning.

 

Cheers

Damien

@Steven Collier , I tried this limited access setting for SharePoint once and it broke all our MAM-only Mobile devices' access to OneDrive.  Started prompting users to enroll in Intune if they wanted to be able to access their OneDrive files.  Needless to say I had to roll back the change and re-activate a bunch of mobile devices for MAM-only.  At the time Microsoft was as surprised as I was (this was about 3 years ago) and said they would try to fix this cross-over issue between personal computers and personal devices, but from the article you linked it appears they are treating it as a feature now and not a bug so I assume this is never going to change now. This is disappointing for those of us that get all the security we need from Application Protection policies (MAM) and don't need the extra aggro of device enrollment, but still would like to allow limited SharePoint access on users' personal computers.   

Hi @Derek Pickell, this is a very old thread from over 2 years ago, the options are very different now.  MIP has largely replaced AIP and is now available in the browser.

Hi @Steven Collier , yes sorry I was venting my spleen on this thread because my boss recently asked me why we can't enable limited SharePoint access on personal computers for our staff and I was disappointed to find that even after all this time this option would still break our mobile MAM-only solution.  Microsoft has just called it out (device enrollment) as an additional security feature so we have no choice but to implement it if we want limited SharePoint access.  It rankles because the way we have MAM policies currently configured is sufficient to prevent data exfiltration.  Device Enrollment, while preferred by me as an Admin, is not preferred by the thousands of personal device users we have on staff.  I now have to explain to my management that we have to choose between mobile device enrollment and limited sharepoint access.  We have DLP projects working on MIP but that won't prevent data downloads to personal devices which is what they are most concerned with.

@Derek Pickell 

 

I'm not really an expert in that area, but the SharePoint restrictions trigger Conditional Access policies, is it not possible to change the conditions on the policy to exclude iOS and Android but keep blocking Windows and MAC.

 

Like this ...

 

Screenshot 2020-12-14 205801.png