SOLVED

DLP specific location OneDrive

%3CLINGO-SUB%20id%3D%22lingo-sub-2108292%22%20slang%3D%22en-US%22%3EDLP%20specific%20location%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2108292%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20I%20understand%20that%20within%20the%20DLP%20one%20can%20specify%20the%20locations.%20I%20want%20to%20set%20up%20a%20scenario%20for%20specific%20OneDrive%20accounts.%20Searching%20sites%20on%20the%20subject%2C%20you%20can%20conclude%20that%20to%20attach%20an%20account%20I%20need%20its%20URL%20in%20the%20following%20format%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fxxxxxxxxxxx-my.sharepoint.com%2Fpersonal%2Firvins_domain_com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fxxxxxxxxxxx-my.sharepoint.com%2Fpersonal%2Firvins_domain_com%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20when%20I%20hit%20search%20it%20tells%20me%20only%20the%20following%3A%20No%20data%20availabe%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20account%20with%20which%20I%20make%20these%20settings%20has%20the%20following%20roles%3A%20Global%20admin%20and%20Sharepoint%20Admin.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHas%20anyone%20been%20able%20to%20make%20this%20configuration%3F%20Am%20I%20missing%20some%20special%20role%3F%20In%20the%20Microsoft%20documentation%20they%20do%20not%20specify%20that%20point%20and%20they%20do%20not%20have%20examples%20with%20OneDrive.%20Thanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2108292%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EData%20Loss%20Prevention%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDLP%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2113869%22%20slang%3D%22en-US%22%3ERe%3A%20DLP%20specific%20location%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2113869%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20solution%20was%20as%20simple%20as%20assigning%20yourself%20the%20SharePoint%20Admin%20role.%20Within%20the%20documentation%20they%20could%20add%20this%20small%20requirement%20and%20I%20think%20it%20would%20clarify%20the%20doubt%20to%20many.%20Case%20closed!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2108436%22%20slang%3D%22en-US%22%3ERe%3A%20DLP%20specific%20location%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2108436%22%20slang%3D%22en-US%22%3EThanks%20for%20the%20answer%20Vasil%2C%20I%20thought%20that%20being%20a%20SharePoint%20administrator%20was%20more%20than%20enough.%20Now%2C%20where%20can%20I%20configure%20the%20last%20thing%20you%20mention%20%22view-only%22%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2108352%22%20slang%3D%22en-US%22%3ERe%3A%20DLP%20specific%20location%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2108352%22%20slang%3D%22en-US%22%3E%3CP%3EThere%20are%20some%20obvious%20issues%20with%20the%20new%20UI%20that%20MS%20should%20hopefully%20address%2C%20but%20do%20make%20sure%20that%20you%20are%20entering%20the%20correct%20URL.%20It%20will%20not%20always%20match%20the%20UPN%20of%20the%20user%2C%20or%20the%20default%20domain%2C%20so%20make%20sure%20you%20verify%20it%20first.%20There%20are%20also%20some%20methods%20to%20enumerate%20ODFB%20sites%2C%20the%20easiest%20one%20being%20detailed%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fonedrive%2Flist-onedrive-urls%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fonedrive%2Flist-onedrive-urls%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EApart%20from%20that%2C%20if%20I%20remember%20correctly%20you%20will%20need%20at%20least%20%22view-only%22%20permissions%20to%20add%20a%20given%20site%2FODFB%20URL.%20Without%20such%20permissions%2C%20it's%20a%20hit%20or%20miss.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi, I understand that within the DLP one can specify the locations. I want to set up a scenario for specific OneDrive accounts. Searching sites on the subject, you can conclude that to attach an account I need its URL in the following format:

https://xxxxxxxxxxx-my.sharepoint.com/personal/irvins_domain_com/

 

But when I hit search it tells me only the following: No data availabe

 

The account with which I make these settings has the following roles: Global admin and Sharepoint Admin.

 

Has anyone been able to make this configuration? Am I missing some special role? In the Microsoft documentation they do not specify that point and they do not have examples with OneDrive. Thanks!

3 Replies

There are some obvious issues with the new UI that MS should hopefully address, but do make sure that you are entering the correct URL. It will not always match the UPN of the user, or the default domain, so make sure you verify it first. There are also some methods to enumerate ODFB sites, the easiest one being detailed here: https://docs.microsoft.com/en-us/onedrive/list-onedrive-urls

 

Apart from that, if I remember correctly you will need at least "view-only" permissions to add a given site/ODFB URL. Without such permissions, it's a hit or miss.

Thanks for the answer Vasil, I thought that being a SharePoint administrator was more than enough. Now, where can I configure the last thing you mention "view-only"?
best response confirmed by Christopher Campos (Occasional Contributor)
Solution

The solution was as simple as assigning yourself the SharePoint Admin role. Within the documentation they could add this small requirement and I think it would clarify the doubt to many. Case closed!