Skip to main content

βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌπŸ”“CP - OneDrive - Allow personal OneDrive

What this page is about πŸ”“β€‹

This policy is not the default. It is also not meant for broad deployment.

Instead, this is the countermeasure to override the βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌCP - OneDrive - Block personal OneDrive policy β€” but only for those users you explicitly allow.

Why? Because Intune applies the most restrictive setting, and if you’ve applied a block policy to all users, simply removing someone from that group won’t remove the block.
You’ll need to apply a policy that deliberately unblocks it.


Why this is necessary πŸ€”β€‹

Let’s say:

  • You block personal OneDrive sync for everyone (good!)
  • The CEO wants access anyway (okay, fine πŸ˜‘)
  • You exclude the CEO from the block policy group

Still blocked.
Why? Because Intune remembers the original setting.

➑️ Enter this policy:
You assign it directly to the exclusion group (πŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“Group - Personal OneDrive Allowed users), and it actively says:

"Hey Intune, it’s okay β€” this one can use personal OneDrive."


πŸ› οΈ OneDrive Personal Account Allow Configuration​

SettingStateDetails
Block syncing of personal OneDrive accountsDisabledRequired to override any previously assigned β€œEnabled” setting

πŸ‘₯ Group Assignments​

βœ… Included groups:​

❌ Excluded groups:​

  • (none) β€” only assign to those who need the exception

πŸ’‘ SuperVision Tip​

SuperVision handles identity and group management across tenants.
This policy uses group membership β€” not tags β€” so SuperVision helps by:

⚠️ Be sure to:

  • Document who belongs in this group
  • Have written approval from the customer
  • Avoid β€œaccidental exceptions” at all costs

Final Thoughts πŸ”šβ€‹

This is not a "green light for everyone" config. It’s a targeted override used only when someone absolutely needs access to their personal OneDrive account β€” and you're willing to take that risk.

Use this only:

  • In combination with the block policy
  • With strict governance
  • With the audit trail to back it up

Want control? Start here with the block policy
Want exceptions? Use this β€” carefully. πŸ”“