SOLVED

Office 365 - Unable to Download, print, or sync when using Chrome or Firefox (but works in IE)

%3CLINGO-SUB%20id%3D%22lingo-sub-287624%22%20slang%3D%22en-US%22%3EOffice%20365%20-%20Unable%20to%20Download%2C%20print%2C%20or%20sync%20when%20using%20Chrome%20or%20Firefox%20(but%20works%20in%20IE)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-287624%22%20slang%3D%22en-US%22%3E%3CP%3EI%20recently%20configured%20Conditional%20Access%20in%20Office%20365%20by%20selecting%20%22Allow%20limited%2C%20web-only%20access%22%20in%20the%20SharePoint%20Admin%20Center%2C%20under%20%22Unmanaged%20devices).%26nbsp%3B%20All%20the%20devices%20in%20question%20are%20managed%20and%20appear%20under%20Azure%20AD%20Devices%20as%20%22Hybrid%20Azure%20AD%20Joined%22.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20issue%20is%20that%20if%20I%20go%20to%20Office.com%20in%20Chrome%20of%20Firefox%2C%20and%20then%20go%20to%20OneDrive%2C%20I%20receive%20the%20message%20stating%20%22Your%20organization%20doesn't%20allow%20you%20to%20download%2C%20print%2C%20or%20sync...%22%20However%2C%20if%20I%20go%20to%20Office.com%20in%20IE%20and%20then%20go%20to%20OneDrive%2C%20I%20do%20not%20receive%20that%20message%2C%20and%20I%20have%20full%20functionality.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHas%20anyone%20encountered%20this%20before%3F%26nbsp%3B%20If%20I%20disable%20the%20%22%5BSharePoint%20Admin%20Center%5DUse%20app-enforced%20Restrictions%20for%20browser%20access%22%2C%20I%20have%20no%20issues%2C%20so%20I%20know%20it's%20directly%20tied%20to%20that.%26nbsp%3B%20I%20just%20can't%20figure%20out%20why%20Chrome%2FFirefox%20do%20not%20work%20properly.%26nbsp%3B%20Thank%20you%20in%20advance!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdditional%20info%3A%3C%2FP%3E%3CP%3EWindows%2010%20LTSB%20(1607)%3C%2FP%3E%3CP%3EChrome%2070.0.3538%20(latest)%3C%2FP%3E%3CP%3EFirefox%2060.3%20(latest)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-287624%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOneDrive%20for%20Business%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-297739%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20-%20Unable%20to%20Download%2C%20print%2C%20or%20sync%20when%20using%20Chrome%20or%20Firefox%20(but%20works%20in%20IE)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-297739%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can%20also%20take%20a%20look%26nbsp%3Bat%20the%20Windows%2010%20Accounts%20plugin%20for%20Chrome%20to%20help%20with%20this.%20I%20thought%20there%20was%20one%20for%20Firefox%20as%20well%2C%20but%20I'm%20not%20able%20to%20find%20it%20right%20now.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EChrome%20-%20%3CA%20href%3D%22https%3A%2F%2Fchrome.google.com%2Fwebstore%2Fdetail%2Fwindows-10-accounts%2Fppnbnpeolgkicgegkbkbjmhlideopiji%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fchrome.google.com%2Fwebstore%2Fdetail%2Fwindows-10-accounts%2Fppnbnpeolgkicgegkbkbjmhlideopiji%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-288866%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20-%20Unable%20to%20Download%2C%20print%2C%20or%20sync%20when%20using%20Chrome%20or%20Firefox%20(but%20works%20in%20IE)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-288866%22%20slang%3D%22en-US%22%3E%3CP%3EReceived%20an%20answer%20back%20from%20Microsoft%2C%20with%20a%20link%20to%20an%20article%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Fcontrol-access-from-unmanaged-devices%3FredirectSourcePath%3D%25252fen-us%25252farticle%25252fControl-access-from-unmanaged-devices-5ae550c4-bd20-4257-847b-5c20fb053622%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Fcontrol-access-from-unmanaged-devices%3FredirectSourcePath...%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20below%20pasted%20statement%20basically%20means%20we%20need%20to%20use%20Edge%20or%20IE%20with%20Windows%2010%2C%20in%20order%20to%20have%20full%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22inline-tag%20mode-research%20completed%20inline-tag--auto%22%3EO365%3C%2FSPAN%3E%26nbsp%3B%26nbsp%3Bfunctionality%20online%20(or%20the%20users%20can%20just%20use%20the%20desktop%20apps%2C%20which%20all%20managed%20devices%20have).%20Just%20wanted%20to%20put%20this%20in%20here%2C%20in%20case%20it%20can%20help%20anyone%20else%20in%20the%20future!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22Blocking%20or%20limiting%20access%20on%20unmanaged%20devices%20relies%20on%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22inline-tag%20mode-research%20completed%20inline-tag--auto%22%3EAzure%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EAD%20conditional%20access%20policies.%20Learn%20about%20Azure%20AD%20licensing%20For%20an%20overview%20of%20conditional%20access%20in%20Azure%20AD%2C%20see%20Conditional%20access%20in%20Azure%20Active%20Directory.%20For%20info%20about%20recommended%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22inline-tag%20mode-research%20completed%20inline-tag--auto%22%3ESharePoint%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eaccess%20policies%2C%20see%20Policy%20recommendations%20for%20securing%20SharePoint%20sites%20and%20files.%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EIf%20you%20limit%20access%20on%20unmanaged%20devices%2C%20users%20on%20managed%20devices%20who%20have%20the%20following%20browser%20and%20operating%20system%20combinations%20will%20also%20have%20limited%20access%3A%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EChrome%2C%20Firefox%2C%20or%20any%20other%20browser%20besides%20Microsoft%20Edge%20and%20Microsoft%20Internet%20Explorer%20on%20Windows%2010%20or%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22inline-tag%20mode-research%20completed%20inline-tag--auto%22%3EWindows%20Server%202016%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CBR%20%2F%3EFirefox%20in%20Windows%208.1%2C%20Windows%207%2C%20Windows%20Server%202012%20R2%2C%20Windows%20Server%202012%2C%20or%20Windows%20Server%202008%20R2%22%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

I recently configured Conditional Access in Office 365 by selecting "Allow limited, web-only access" in the SharePoint Admin Center, under "Unmanaged devices).  All the devices in question are managed and appear under Azure AD Devices as "Hybrid Azure AD Joined".

 

My issue is that if I go to Office.com in Chrome of Firefox, and then go to OneDrive, I receive the message stating "Your organization doesn't allow you to download, print, or sync..." However, if I go to Office.com in IE and then go to OneDrive, I do not receive that message, and I have full functionality.

 

Has anyone encountered this before?  If I disable the "[SharePoint Admin Center]Use app-enforced Restrictions for browser access", I have no issues, so I know it's directly tied to that.  I just can't figure out why Chrome/Firefox do not work properly.  Thank you in advance!

 

Additional info:

Windows 10 LTSB (1607)

Chrome 70.0.3538 (latest)

Firefox 60.3 (latest)

2 Replies
Highlighted
Solution

Received an answer back from Microsoft, with a link to an article - https://docs.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices?redirectSourcePath...

 

The below pasted statement basically means we need to use Edge or IE with Windows 10, in order to have full O365  functionality online (or the users can just use the desktop apps, which all managed devices have). Just wanted to put this in here, in case it can help anyone else in the future!

 

"Blocking or limiting access on unmanaged devices relies on Azure AD conditional access policies. Learn about Azure AD licensing For an overview of conditional access in Azure AD, see Conditional access in Azure Active Directory. For info about recommended SharePoint access policies, see Policy recommendations for securing SharePoint sites and files. If you limit access on unmanaged devices, users on managed devices who have the following browser and operating system combinations will also have limited access: 

 

Chrome, Firefox, or any other browser besides Microsoft Edge and Microsoft Internet Explorer on Windows 10 or Windows Server 2016 
Firefox in Windows 8.1, Windows 7, Windows Server 2012 R2, Windows Server 2012, or Windows Server 2008 R2"

Highlighted

You can also take a look at the Windows 10 Accounts plugin for Chrome to help with this. I thought there was one for Firefox as well, but I'm not able to find it right now.

 

Chrome - https://chrome.google.com/webstore/detail/windows-10-accounts/ppnbnpeolgkicgegkbkbjmhlideopiji