Skip to main content

βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌCP - OneDrive - Block personal OneDrive

What this page is about πŸ”’β€‹

By now we all know hackers are out there to exfiltrate data. But let’s not forget: insiders can be just as creative (read: dangerous).

Think:

  • That one colleague who didn’t really click with the team πŸ™„
  • Someone leaving the company (voluntarily... or not) 😬
  • Or just a user who thinks β€œcopying everything to my personal OneDrive is a good backup plan” πŸ“€πŸ’€

And boom β€” data leaves the organization unmanaged.
Cillit Bangβ„’. Bang and the data is gone.

So yes, blocking personal OneDrive accounts is not just a nice-to-have. It’s common sense.


But wait, what if the CEO does want it? πŸ§‘β€πŸ’ΌπŸ“₯​

Of course, sometimes the CEO wants to β€œbring in” something from their private stash. That one folder with decades-old spreadsheets and questionable macros.

In those rare cases, we add them to an exception group.

And to make that crystal clear, we mark this group with β€” yes β€” emojis.
Say hello to your default allow group:

πŸ‘‰ πŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“Group - Personal OneDrive Allowed users

Use this group to exclude specific users from the block policy.


πŸ› οΈ OneDrive Personal Account Block Configuration​

SettingStateDetails
Block syncing of personal OneDrive accountsEnabledPrevents signing in with personal Microsoft accounts in OneDrive

πŸ‘₯ Group Assignments​

βœ… Included groups:​

  • All Users

❌ Excluded groups:​

Why?
Because sometimes business flexibility > full lockdown β€” but we want to control it explicitly.


πŸ’‘ SuperVision Tip​

SuperVision makes user-based group management across multiple tenants ridiculously efficient.

Instead of working with tags, this policy uses a fixed, default group based on IAM.
That means you:

⚠️ Important: Always document who is allowed in this exclusion group.
Make sure your client has signed off on the exact list of users β€” no β€œjust in case” additions. Governance matters here.


πŸ”„ Bonus: the Inverse Policy​

Curious how to undo this policy just as cleanly?

Check out:
πŸ‘‰ βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌπŸ”“CP - OneDrive - Allow personal OneDrive

It’s the inverse of this one β€” unblocking personal accounts in a controlled way when needed.
(Or as we like to say: removing the tattoo, not just hiding it.)


Final Thoughts πŸ”šβ€‹

Personal OneDrive sync is one of those β€œsmall” settings that turns into a giant compliance headache when ignored.

So:

  • Block it by default
  • Allow it with intent
  • Document your exceptions

Because "I just copied it to my own drive for convenience" is not the conversation you want to have during a data breach postmortem.


Secure smart.
Exclude with emoji logic.
And remember: Bang = gone.