Skip to main content

βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌCP - OneDrive - Block other tenant signin

You are either with us or you are not syncing. The OneDrive client accepts your organization's accounts and turns away the tenant someone found behind the couch.

βš™οΈType Configuration profileπŸͺŸPlatform WindowsπŸ§‘β€πŸ’ΌTarget Users
reference-build Β· onedrive-block-other-tenant-signinGolden Master reference
License tier
Business Premium (Intune)
Control plane
Intune Settings Catalog
Scope
Windows, all users
Reversibility
clean-revert, paired inverse

What this policy is about πŸ›‘β€‹

The OneDrive sync client will happily sign in to any Microsoft 365 tenant it is given. This policy tells it to accept accounts from the customer's own tenant only. No mystery organizations, no "I just needed to grab something real quick", no second tenant riding along on a managed device.

It is set with a tenant restriction: the client is pinned to one tenant ID, and everything else is refused.

πŸ€” One legitimate cloud, not ten

The point is not to be difficult. It is that a managed device should sync corporate data to exactly one place you control. Every additional tenant the client will talk to is another cloud you are now responsible for and cannot see into.

Why this matters β˜οΈβ€‹

When Bob from Accounting signs into his old startup's tenant on his work laptop, your quarterly reports can sync to a OneDrive you do not manage, in an organization you cannot audit, protected by controls you have never seen. Throw a couple of mergers into the mix and suddenly data is flowing in ten directions with nobody accountable for any of it.

Pinning the client to a single tenant closes that off. Cross-tenant collaboration still happens the governed way, through sharing and guest access; it just does not happen by a personal account quietly syncing a folder somewhere else.

πŸ› οΈ Configuration​

Where: Intune admin center β†’ Devices β†’ Configuration β†’ Create β†’ Windows β†’ Settings catalog β†’ OneDrive.

SettingValue
Allow syncing OneDrive accounts for only specific organizationsEnabled
Tenant IDPer-environment variable (never a hardcoded one)
Assignment, includeAll users
Assignment, excludeπŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“Group - Multi tenant OneDrive Allowed users

Caveats βš οΈβ€‹

Never paste your own Tenant ID. This setting needs a tenant ID, and hardcoding one into a blueprint that ships to every customer pins all of them to a single cloud, the wrong one. Use a per-environment variable so each tenant restricts to itself. This is the exact mistake that turns "rollout" into "incident".

The genuine cross-tenant case has a governed path. Mergers, shared workloads, a user legitimately active in two tenants: those go through the βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌπŸ”“CP - OneDrive - Allow other tenant signin inverse policy and its exception group, with written approval, not by loosening this for everyone.

Sharing still works. This restricts the sync client, not sharing links or guest access. Nobody loses the ability to collaborate with an outside org the proper way; they lose the ability to sync a whole second tenant onto a managed machine.

License and reversibility. Included in Business Premium. Clean-revert on its own, though the exception path is the paired inverse rather than plain unassignment.


Sync corporate data to exactly one cloud you control. For anyone who really needs another, there is the exception policy, written approval, and a raised eyebrow. πŸ›‘