Skip to main content

πŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“βš™οΈGroup - Multi tenant OneDrive Allowed users

What this group does πŸ§ͺ​

Being in this group means one thing:

β€œI'm trusted (or at least important enough) to sign into OneDrive using another tenant.”

That’s right. While the default policy
βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌCP - OneDrive - Block other tenant signin says β€œnope, stick to your own tenant”,
this group β€” combined with the
βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌπŸ”“CP - OneDrive - Allow other tenant signin policy β€” says:

🧞 β€œOkay, fine. But only for you.”


πŸ› οΈ Group Configuration​

SettingValue
Group nameπŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“Group - Multi tenant OneDrive Allowed users
Group descriptionUsers in this group are explicitly allowed to sync OneDrive accounts from other tenants. This overrides the block policy. Membership requires documented customer approval.
Group typeSecurity
Membership typeAssigned

πŸ’‘ SuperVision Tip​

This group is manually assigned β€” but that doesn’t mean it has to be a mess.

SuperVision supports user management across tenants, so you can assign this group consistently via:

  • dynamic views
  • rule-based grouping
  • and automation across environments

All while using a recognizable naming standard (πŸ›‘οΈ, πŸ‘ˆ, πŸ”“) for clear intent.

✍️ Still, make sure the customer signs off. Not just verbally β€” we mean actual documentation.


🎯 Purpose​

Used as an exception mechanism for users in:

  • Mergers & acquisitions (πŸ‘”πŸ“ˆ)
  • Multi-tenant collaboration environments (🌐)
  • Situations where β€œjust block everything” doesn't quite work

This group is assigned to users who need access β€” not just want access.


⚠️ Governance matters​

If you add someone to this group:

  • You should know why
  • The customer should know why
  • And you should have a signed piece of paper somewhere that proves it

If you can’t explain who’s in this group during an audit... maybe don’t add them in the first place.



πŸ•·οΈ With great tenant access comes great compliance risk.