Limit onedrive to only sync to computers in the domain, add exceptions

%3CLINGO-SUB%20id%3D%22lingo-sub-1280889%22%20slang%3D%22zh-CN%22%3ELimit%20onedrive%20to%20only%20sync%20to%20computer%20in%20the%20domain%2C%20add%20exceptions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1280889%22%20slang%3D%22zh-CN%22%3E%3CP%3EAfter%20Using%20Set-SPOTenantPoint%20Point%20Point%20Restrict%20Limited%20-Enable%20-Domain%20Guids%20to%20restrict%20onedrive%20to%20computer%20in%20the%20domain%20only%2C%20add%20an%20exception%20whitelist%20for%20individual%20computer%20to%20allow%20vein%2C%20exception%20rules%20can%20for%20for%20accounts%2C%20or%20for%20computers%2C%20or%20any%20other%20exception%2C%20for%20IP%20IP%20IP%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1280889%22%20slang%3D%22zh-CN%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EFiles%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ELimits%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOneDrive%20for%20Business%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EStorage%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESync%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1281330%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20onedrive%20to%20only%20sync%20to%20computers%20in%20the%20domain%2C%20add%20exceptions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1281330%22%20slang%3D%22en-US%22%3E%3CP%3EThere's%20no%20such%20thing%20as%20exceptions%2C%20only%20machines%20joined%20to%20the%20domain(s)%20you%20specify%20will%20be%20allowed.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1287599%22%20slang%3D%22zh-CN%22%3ERe%3A%20Limit%20onedrive%20to%20only%20sync%20to%20computer%20in%20the%20domain%2C%20add%20exceptions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1287599%22%20slang%3D%22zh-CN%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWell%2C%20thank%20you%20for%20your%20reply%2C%20there%20are%20companies%20to%20provide%20mac%20machine%2C%20there%20are%20anis%20private%20mac%20machine%2C%20how%20to%20to%20to%20the%20private%20private%20machine%20machine%20for%20the%20business%2C%20allow%20the%20company's%20mac%20machine%20machine%20inga%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1288767%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20onedrive%20to%20only%20sync%20to%20computers%20in%20the%20domain%2C%20add%20exceptions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1288767%22%20slang%3D%22en-US%22%3E%3CP%3EMac%20machines%20are%20not%20affected%20by%20default%2C%20as%20explained%20in%20the%20documentation%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fsharepoint-online%2Fset-spotenantsyncclientrestriction%3Fview%3Dsharepoint-ps%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fsharepoint-online%2Fset-spotenantsyncclientrestriction%3Fview%3Dsharepoint-ps%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20need%20to%20specify%20additional%20switch%20if%20you%20want%20to%20block%20them%2C%20otherwise%20they%20can%20still%20connect%20regardless%20of%20any%20domain%20restrictions.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1328809%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20onedrive%20to%20only%20sync%20to%20computers%20in%20the%20domain%2C%20add%20exceptions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1328809%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3EDo%20you%20know%20a%20way%20to%20add%20exceptions%20or%20bypass%20this%20for%20Azure%20AD%20Joined%20devices.%3CBR%20%2F%3EA%20customer%20is%20currently%20switchting%20his%20clients%20from%20his%20old%20domains%20to%20a%20single%20new%20one%20and%20is%20using%20autopilot%20deployment%20with%20only%20azure%20ad%20join%20(not%20hybrid%20joined)%20and%20therefore%20the%20clients%20are%20getting%20blocked%20(since%20they%20are%20in%20a%20workgroup).%3CBR%20%2F%3EI%20know%20we%20could%20technically%20go%20and%20hybrid%20join%20them%20with%20domain%20join%20configuration%20profile%2C%20but%20that%20is%20not%20the%20intended%20way%20to%20go.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

After using Set-SPOTenantPointSyncRestrictLimitedRestrict -Enable -Domain Guids to restrict onedrive to computers in the domain only, add an exception whitelist for individual computers to allow synchronization, exception rules can be for accounts, or for computers, or any other exception, for IP IP

4 Replies
Highlighted

There's no such thing as exceptions, only machines joined to the domain(s) you specify will be allowed.

Highlighted

@Vasil Michev 

Well, thank you for your reply, there are companies to provide mac machine, there are employees private mac machine, how to prevent private mac machine sync onedrive for business information, allow the company's mac machine synchronization

Highlighted

Mac machines are not affected by default, as explained in the documentation: https://docs.microsoft.com/en-us/powershell/module/sharepoint-online/set-spotenantsyncclientrestrict...

 

You need to specify additional switch if you want to block them, otherwise they can still connect regardless of any domain restrictions.

Highlighted

@Vasil Michev 
Do you know a way to add exceptions or bypass this for Azure AD Joined devices.
A customer is currently switchting his clients from his old domains to a single new one and is using autopilot deployment with only azure ad join (not hybrid joined) and therefore the clients are getting blocked (since they are in a workgroup).
I know we could technically go and hybrid join them with domain join configuration profile, but that is not the intended way to go.