βοΈπͺπ§βπΌCP - OneDrive - Block personal OneDrive
No personal Microsoft accounts in the OneDrive client. Cillit Bang, and the data is gone, unless you close the drain first.
What this policy is about πβ
Attackers want to exfiltrate data, but so, occasionally, do insiders, and they are far more creative about it. The colleague who never quite clicked with the team, the one working their notice, or just the well-meaning user who decides copying everything to their private OneDrive is "a backup plan". Same result: company data walks out through a consumer account you cannot see, manage, or claw back.
This policy blocks personal Microsoft accounts in the OneDrive sync client outright. The corporate account still works; the personal one stops being a side door for your files.
Sometimes a genuine exception exists (the exec bringing in a folder of ancient spreadsheets and questionable macros). That is what the exception group is for. This is a default block with a deliberate, documented way out, not a wall with no gate.
Why this matters βοΈβ
You do not control a personal OneDrive. You do not know where it lives, who else touches it, or what happens to it after the person leaves. "I just copied it to my own drive for convenience" is not a sentence you want to hear for the first time during a breach post-mortem, and by then the quarterly reports have already synced to someone's old startup account.
Blocking it is cheap, it is invisible to honest users, and it closes one of the most common self-service data-leak paths in any tenant. Low friction, high payoff.
π οΈ Configurationβ
Where: Intune admin center β Devices β Configuration β Create β Windows β Settings catalog β OneDrive.
| Setting | Value |
|---|---|
| Block syncing of personal OneDrive accounts | Enabled |
| Assignment, include | All users |
| Assignment, exclude | π‘οΈπ§βπΌππβοΈGroup - Personal OneDrive Allowed users |
The exclusion group is the front half of the exception. Removing someone from it is not enough on its own, because this setting tattoos, see the caveat below.
Caveats β οΈβ
Exclusion is not undo (this is why there is an inverse policy). This setting writes to a tattooing surface: on a device that already received the block, simply taking a user out of the assignment does not remove the setting. To actually re-enable personal sync for an approved exception you must assign the βοΈπͺπ§βπΌπCP - OneDrive - Allow personal OneDrive inverse policy to the same group. Remove the tattoo, do not just stop drawing new ones.
The exception list is a governance artefact. Every member of the allowed group is a signed-off, documented decision, not a "just in case" addition. Have the customer approve the exact list and review it, because an exception nobody remembers granting is a leak with paperwork missing.
It targets the client, not the browser. This blocks the sync app. A determined user can still upload to a personal account through a web browser, which is a job for the broader data-loss and web-filtering story, not this one setting. Useful to say out loud so nobody mistakes this for total DLP.
License and reversibility. Included in Business Premium. Tattooing: plan the paired inverse for exceptions rather than relying on unassignment.
π Relatedβ
- βοΈπͺπ§βπΌπCP - OneDrive - Allow personal OneDrive: the inverse that cleanly unblocks approved exception users.
- βοΈπͺπ»CP - OneDrive - Configuration: the baseline that manages the corporate account this policy protects.
Block it by default, allow it with intent, document every exception, and remember: Cillit Bang, and the data is gone. π