SOLVED

Restrict Sharepoint access through Teams on mobile devices

%3CLINGO-SUB%20id%3D%22lingo-sub-1440315%22%20slang%3D%22en-US%22%3ERestrict%20Sharepoint%20access%20through%20Teams%20on%20mobile%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1440315%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%2C%20is%20there%20a%20way%20to%20restrict%20access%20to%20SharePoint%20content%20through%20Teams%20interface%20(Files%20Tab)%20on%20unmanaged%20mobile%20devices.%20There%20is%20such%20a%20need%20as%20I%20want%20such%20users%20(on%20un%20managed%20devices)%20to%20access%20Teams%20for%20calls%2Fvideo%20and%20may%20be%20chat%20but%20not%20to%20access%20SharePoint%20fIles%20and%20folders%20and%20maybe%20similarly%20not%20the%20Onedrive%26nbsp%3B%20files.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20enforced%20conditional%20access%20and%20also%20as%20SharePoint%20admin%20blocked%20access%20to%20SharePoint%20from%20unmanaged%20devices%20but%20it%20still%20doesn't%20seem%20to%20restrict%20the%20access.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1440315%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESharepoint%20and%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1441432%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Sharepoint%20access%20through%20Teams%20on%20mobile%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1441432%22%20slang%3D%22en-US%22%3EYou%20can%20control%20this%20from%20the%20SP%20admin%20center%20to%20be%20reflected%20for%20both%20OD4B%20and%20SharePoint%20through%20the%20SP%20admin%20center%2C%20and%20you%20can%20have%20more%20control%20over%20the%20options%20available%20through%20AAD.%20Follow%20this%20article%20for%20more%20info%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Fcontrol-access-from-unmanaged-devices%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsharepoint%2Fcontrol-access-from-unmanaged-devices%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1442407%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Sharepoint%20access%20through%20Teams%20on%20mobile%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1442407%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F532869%22%20target%3D%22_blank%22%3E%40derhallim%3C%2FA%3E%26nbsp%3BThanks%20for%20the%20response.%20However%2C%20this%20is%20something%20we%20have%20already%20done.%20Result%20is%20that%20%3CSTRONG%3Eusers%20from%20unmanaged%20devices%3C%2FSTRONG%3E%20are%20%3CSTRONG%3Estill%20able%20to%20access%20through%20Teams%3C%2FSTRONG%3E%20(Files%20Tab)%20all%20the%20files%20and%20folders%20that%20reside%20in%20SharePoint%20sites.%20Requirement%20is%20to%20block%20access%20to%26nbsp%3B%20SharePoint%20while%20allowing%20MS%20Teams%20for%20communication%2C%20i.e.%2C%20chat%2C%20meeting%20%2C%20video%20calls.%20Cant%20think%20that%20there%20is%20a%20gap%20in%20Microsoft's%20access%20policies%20for%20Teams%20and%20SharePoint....%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1442494%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Sharepoint%20access%20through%20Teams%20on%20mobile%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1442494%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F688901%22%20target%3D%22_blank%22%3E%40AVVerifile%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20managed%20to%20achieve%20this%20with%20a%20separate%20Conditional%20access%20policy%20which%20excluded%20any%20hybrid%20joined%20device%20or%20compliant%20device.%26nbsp%3B%20Coupling%20this%20with%20an%20app%20protection%20policy%20to%20prevent%20any%20potential%20data%20leakage%20via%20copy%20paste%20etc%20for%20teams%20means%20that%20we%20have%20users%20with%20unmanaged%20devices%20accessing%20teams%20but%20not%20being%20able%20to%20potentially%20leak%20data%2F%20access%20documents%20on%20devices%20outside%20of%20the%20organisation.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUsers%20and%20groups%26nbsp%3B%3C%2FP%3E%3CP%3Especify%20your%20scope%20here%20of%20whom%20you%20wish%20for%20this%20policy%20to%20apply%20to.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECloud%20apps%20or%20actions%26nbsp%3B%3C%2FP%3E%3CP%3EInclude%20only%20sharepoint%20online%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EConditions%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3BDevice%20platform%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20device%20-%20This%20is%20so%20it%20affects%20if%20a%20user%20tries%20to%20access%20sharepoint%20content%20via%20any%20unmanaged%20device.%3C%2FP%3E%3CP%3ELocations%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20location%26nbsp%3B%20-%20did%20not%20include%20trusted%20locations%20due%20to%20not%20wanting%20an%20unauthorized%20device%20being%20able%20to%20access%20this%20inside%20the%20corporate%20network.%3C%2FP%3E%3CP%3EClient%20apps%26nbsp%3B%3C%2FP%3E%3CP%3EInclude%20both%20browser%20and%20mobile%20apps%20and%20desktop%20clients.%20only%20tick%20box%20excluded%20was%20apply%20policy%20only%20to%20supported%20platforms.%26nbsp%3B%3C%2FP%3E%3CP%3EDevice%20state%26nbsp%3B%3C%2FP%3E%3CP%3EInclude%20all%20device%20state%20but%20exclude%20compliant%20and%20hybrid%20joined%20devices%20from%20this%20policy%3C%2FP%3E%3CP%3EAccess%20controls%3C%2FP%3E%3CP%3Eblock%20access%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%3C%2FP%3E%3CP%3EWill%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi , is there a way to restrict access to SharePoint content through Teams interface (Files Tab) on unmanaged mobile devices. There is such a need as I want such users (on un managed devices) to access Teams for calls/video and may be chat but not to access SharePoint fIles and folders and maybe similarly not the Onedrive  files. 

 

Have enforced conditional access and also as SharePoint admin blocked access to SharePoint from unmanaged devices but it still doesn't seem to restrict the access.  

3 Replies
You can control this from the SP admin center to be reflected for both OD4B and SharePoint through the SP admin center, and you can have more control over the options available through AAD. Follow this article for more info:

https://docs.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices

@derhallim Thanks for the response. However, this is something we have already done. Result is that users from unmanaged devices are still able to access through Teams (Files Tab) all the files and folders that reside in SharePoint sites. Requirement is to block access to  SharePoint while allowing MS Teams for communication, i.e., chat, meeting , video calls. Cant think that there is a gap in Microsoft's access policies for Teams and SharePoint....

best response confirmed by AVVerifile (New Contributor)
Solution

@AVVerifile 

 

We managed to achieve this with a separate Conditional access policy which excluded any hybrid joined device or compliant device.  Coupling this with an app protection policy to prevent any potential data leakage via copy paste etc for teams means that we have users with unmanaged devices accessing teams but not being able to potentially leak data/ access documents on devices outside of the organisation.

 

Users and groups 

specify your scope here of whom you wish for this policy to apply to.

 

Cloud apps or actions 

Include only sharepoint online 

 

Conditions 

 Device platform 

Any device - This is so it affects if a user tries to access sharepoint content via any unmanaged device.

Locations 

Any location  - did not include trusted locations due to not wanting an unauthorized device being able to access this inside the corporate network.

Client apps 

Include both browser and mobile apps and desktop clients. only tick box excluded was apply policy only to supported platforms. 

Device state 

Include all device state but exclude compliant and hybrid joined devices from this policy

Access controls

block access

 

Cheers

Will