Sep 26 2023 01:07 AM
I'm using OneDrive for business client sync app in a very tightly controlled environment. We have the app deployed machine wide (per machine as opposed to per user). Our security teams do not want to allow the update scheduled task to access the internet locations required to update the app. As such, they have asked me to come up with a solution to keep it up to date offline.
I have MECM in my environment and all my machines have line of sight of our corporate network (either on-prem or via VPN).
What are my options here? As far as I can see it’s as follows:
Any alternatives/ideas!?
Sep 26 2023 01:18 AM
Hi @shocko,
Your plan to use a MECM scripted task to run OneDriveSetup.exe /update from a UNC/HTTP location hosted by you is a good solution.
This solution will ensure that all of your managed devices are always running the latest version of the OneDrive for Business client sync app, even if they do not have internet access.
Here are some alternatives (or other ideas) you can try to use:
If you have a large number of managed devices or if you need to automate the update process, then I recommend using a MECM scripted task or a third-party patch management solution.
If you only have a small number of managed devices or if you do not need to automate the update process, then you can manually update the OneDrive for Business client sync app on each device.
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
Sep 26 2023 01:21 AM
@shocko This is doomed to failure like all attempts to second-guess cloud-sync services.
It's not just a matter of keeping files up to date, but all the sharing permissions, comments and other service states that connect those files.
I'm all for security, but this request will cripple how the Microsoft 365 environment works.
They either need to come up with a total on-prem solution or even send everyone back to the 20th century to a file-server.
Sep 30 2023 12:21 PM
Sep 30 2023 12:23 PM