Mar 18 2022 07:11 AM
Mar 18 2022 07:11 AM
Whenever we try to sign in to OneDrive on Azure AD joined computers we get the message "Sorry, OneDrive can't add your folder right now"
It works fine for our on-premises AD joined computers.
We have set "Allow syncing only on computers joined to specific domains" and added the GUIDs for our on-premises domain and the Tenant ID for our AAD. However, the documentation for allow syncing on domain joined computers at Allow syncing only on computers joined to specific domains - OneDrive | Microsoft Docs says "This setting is only applicable to Active Directory domains. It does not apply to Azure AD domains. If you have devices which are only Azure AD joined, consider using a Conditional Access Policy instead."
I don't understand what they are trying to say. We have no Conditional Access Policies set and I didn't think I could create a policy to allow access to OneDrive if it is being prevented somewhere else.
Does anyone know whow to allow OneDrive and SharePoint syncing from Azure AD joined computers?
May 13 2022 06:54 AM
Sep 18 2022 11:10 PM
@JWat12 Yes I got the resolution for this. Usually for some organizations when OneDrive is implemented there is a Sync policy created on Sharepoint admin center talking about OneDrive sync to be allowed only on domain joined computers by providing its Active directory domain as a GUID. So if you are facing sync issue with error like "Sorry, OneDrive cant add your folder right now" on your Azure AD joined device then, follow these steps :
1. go to your Sharepoint admin center -> Settings ->OneDrive Sync and note down your domain GUID.
2. Login to affected device and go to registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\OneDrive
3. Under above key ,If AADJMachineDomainGuid keyname is not present then create it and provide your Domain GUID which you copied in step 1 as a value to this keyname.
4. Close registry
Now try to launch OneDrive desktop app on your device again and see if its moving ahead now. (You can try reboot if required)
If you have multiple machines which are facing issues then create PowerShell script and deploy it from your MDM provider.
Sep 19 2022 07:43 AM
The answer I got from Microsoft is that you need to have the devices AD joined or hybrid joined or you need to use Conditional Access Policies.
Rather than using the OneDrive Sync policy they said to use a different one. In the SharePoint Admin Center go to Policies, Access Control. The Unmanaged Devices policy allows you to block access for unmanaged devices. It defines unmanaged devices as ones that are either hybrid AD joined or Intune managed.
At first I thought this would work for us. All our AAD joined devices are Intune managed and it would be easy enough to hybrid join the rest. However, here is where Microsoft tries a scam. I doesn't say on the Unmanaged Devices Policy page but enabling this requires that every user the policy applies to needs to have an AAD P1 license. Of course there is a good chance that you won't realize that until a year later and MS comes back and asks for payment for all the licenses you need but they don't tell you.
In our case, it would mean purchasing AAD P1 licenses for the 95% of our people who use computers that aren't AAD joined which doesn't make sense for us.