OneDrive Sync for Azure AD Joined Computers

%3CLINGO-SUB%20id%3D%22lingo-sub-3261055%22%20slang%3D%22en-US%22%3EOneDrive%20Sync%20for%20Azure%20AD%20Joined%20Computers%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3261055%22%20slang%3D%22en-US%22%3E%3CP%3EWhenever%20we%20try%20to%20sign%20in%20to%20OneDrive%20on%20Azure%20AD%20joined%20computers%20we%20get%20the%20message%20%22Sorry%2C%20OneDrive%20can't%20add%20your%20folder%20right%20now%22%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20works%20fine%20for%20our%20on-premises%20AD%20joined%20computers.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20set%20%22Allow%20syncing%20only%20on%20computers%20joined%20to%20specific%20domains%22%20and%20added%20the%20GUIDs%20for%20our%20on-premises%20domain%20and%20the%20Tenant%20ID%20for%20our%20AAD.%20However%2C%20the%20documentation%20for%20allow%20syncing%20on%20domain%20joined%20computers%20at%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fonedrive%2Fallow-syncing-only-on-specific-domains%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAllow%20syncing%20only%20on%20computers%20joined%20to%20specific%20domains%20-%20OneDrive%20%7C%20Microsoft%20Docs%3C%2FA%3E%26nbsp%3Bsays%20%22%3CSPAN%3EThis%20setting%20is%20only%20applicable%20to%20Active%20Directory%20domains.%20It%20does%20not%20apply%20to%20Azure%20AD%20domains.%20If%20you%20have%20devices%20which%20are%20only%20Azure%20AD%20joined%2C%20consider%20using%20a%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EConditional%20Access%20Policy%3C%2FA%3E%3CSPAN%3E%26nbsp%3Binstead.%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20don't%20understand%20what%20they%20are%20trying%20to%20say.%20We%20have%20no%20Conditional%20Access%20Policies%20set%20and%20I%20didn't%20think%20I%20could%20create%20a%20policy%20to%20allow%20access%20to%20OneDrive%20if%20it%20is%20being%20prevented%20somewhere%20else.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDoes%20anyone%20know%20whow%20to%20allow%20OneDrive%20and%20SharePoint%20syncing%20from%20Azure%20AD%20joined%20computers%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3261055%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOneDrive%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3369747%22%20slang%3D%22en-US%22%3ERe%3A%20OneDrive%20Sync%20for%20Azure%20AD%20Joined%20Computers%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3369747%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F4770%22%20target%3D%22_blank%22%3E%40John%20Twohig%3C%2FA%3E%26nbsp%3BDid%20you%20get%20any%20resolution%20for%20this%20%3F%20We%20are%20also%20facing%20same%20issue%20on%20our%20only%20Azure%20AD%20joined%20devices%2C%20on%20prem%20domain%20joined%20devices%20are%20working%20fine.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Whenever we try to sign in to OneDrive on Azure AD joined computers we get the message "Sorry, OneDrive can't add your folder right now" 

 

It works fine for our on-premises AD joined computers. 

 

We have set "Allow syncing only on computers joined to specific domains" and added the GUIDs for our on-premises domain and the Tenant ID for our AAD. However, the documentation for allow syncing on domain joined computers at Allow syncing only on computers joined to specific domains - OneDrive | Microsoft Docs says "This setting is only applicable to Active Directory domains. It does not apply to Azure AD domains. If you have devices which are only Azure AD joined, consider using a Conditional Access Policy instead."

 

I don't understand what they are trying to say. We have no Conditional Access Policies set and I didn't think I could create a policy to allow access to OneDrive if it is being prevented somewhere else.

 

Does anyone know whow to allow OneDrive and SharePoint syncing from Azure AD joined computers?

 

 

2 Replies

@John Twohig Did you get any resolution for this ? We are also facing same issue on our only Azure AD joined devices, on prem domain joined devices are working fine.

Dell Support looked at it for a month and then escalated it to Microsoft Support who have had it for over a month. When we ask for an update they always say that it has been escalated to a senior resource.

The annoying thing is that Microsoft Support doesn't seem to have any more access to Microsoft documentation that I do. Initially they just Googled "OneDrive", "Sync", and "domain joined" and sent me links to whatever results they got. I said that I can Google too and if those documents had the answer I wouldn't have needed to open the ticket.

Yet someone at Microsoft knows what can and can't be done. Their documentation clearly states that they recognize the issue so they must have documentation somewhere. There are whole suites of tools out there that allow finding information in large amounts of structured and unstructured data. One would expect Microsoft would know something about that.