Prevent users from Syncing sharepoint document libraries from unmanaged devices

Steel Contributor

I know that i have the option to restrict sharepoint access from unmanaged devices as mentioned on this link Control access from unmanaged devices, but i do not want to do this, as users sometimes access the sharepoint sites from different external PCs, ad restricting this access can result in a lot of problems.

 

But i am not sure if i can have this scenario:-

Can i allow users to access SharePoint from unmanaged devices, but restrict them from Syncing the document libraries using OneDrive or OneDrive for business desktop applications? of course i want them to be able to do the sync from managed devices.

 

In other words can i implement this policy:-

1. Unmanaged devices. users can access sharepoint sites + can NOT Sync

2. Managed devices.     users can access sharepoint sites + can Sync.

7 Replies

@Juan Carlos González Martín wrote:
There is an option on the document library settings to do this: https://support.office.com/en-us/article/stop-syncing-a-library-with-the-onedrive-for-business-app-a...

but this option will work regardless if the user is syncing from managed or from unmanaged devices ? is this correct? i think your answer is not directly related to my question.

Correct, that option as you can read in the support article just hides the sync option for any user.

This thread should be deleted it in no way answers the question "Prevent users from syncing"

Would love to know if this is possible as it fits in perfectly with a zero trust philosophy.

We have over 500 volunteers using their own devices (unmanaged) that need access to SharePoint (via browser) but who present a ransomware risk if they sync SharePoint libraries.

I don't want to disable sync on the individual sites/libraries as staff using InTune managed devices still need to access files offline.

Almost 18 months on and still no answer to this problem which is a bit of a shame... so I'll re-write what I'm trying to achieve below:-

 

We run a native O365/M365 environment with over 1200 users on AzureAD only.

All our files are held in SharePoint/OneDrive.

500+ users are volunteers, using their own equipment that is not managed via Intune.

Staff devices run ThreatLocker zero-trust protection that prevents any code running that hasn't been pre-approved by IT.

 

Ransomware will most likely be picked up on an un-managed device being used by one of our Volunteers.

Only files on the end-users local device will become infected as there is no LAN/Network to spread anything over.

 

If a volunteer syncs a SharePoint site (using OneDrive for Business) onto their local device, we risk the contents of the SP site document library being affected by the ransomware encryption.

 

I would like to do 2 things...

 

Firstly - list all folders within SP libraries that are being synced and by which user.

Secondly - block unmanaged devices from syncing any SP doc libraries. ...or block the use/login of OneDrive for Business on unmanaged devices.

 

The first will assist me in identifying the scale of our current problem/risk.

The second will mitigate the risk almost entirely.

 

If I try to force our volunteers to install Intune management on their personal devices, they would undoubtedly leave us so this is not an option unfortunately.

 

Any ideas would be very gratefully welcomed.