Skip to main content

βš™οΈπŸͺŸπŸ’»CP - OneDrive

What this page is about πŸ“¦β€‹

By now, you probably figured out from the title (and the emojis 🧠) that this policy is about Windows devices. Specifically, OneDrive. Specifically-er, making sure users don’t mess it up.

This configuration is here to make sure:

  • End-users don’t store precious work files only on their local machines
  • Known folders (Desktop, Documents, Pictures) are always backed up to OneDrive
  • There is zero ambiguity about who owns what β€” and how it syncs

Because yes, technically it's "for the user" β€” but actually it's for everyone using the device, not just the first one who logs in before you manage to block BYOD πŸ™ƒ

Why this matters β˜οΈβ€‹

You don't want someone's private recipes, blurry holiday photos or highly sensitive "cat tax" images to end up in the corporate OneDrive by accident. That’s why device-level enforcement is the way to go.

Oh, and we're excluding devices that don’t use OneDrive anyway. Because... obviously. 🎯


πŸ› οΈ OneDrive Configuration Table​

Below you’ll find all settings neatly laid out, with values, context, and copy-pasteable fields. You're welcome.

SettingStateAdditional Info / Values
Allow OneDrive to disable Windows permission inheritance in folders synced read-onlyEnabled
Always use the user's Windows display language when provisioning known folders in OneDriveEnabled
Exclude specific kinds of files from being uploadedEnabledKeywords: Microsoft teams.lnk
Hide the "Deleted files are removed everywhere" reminderEnabled
Prevent users from redirecting their Windows known folders to their PCEnabled
Prompt users to move Windows known folders to OneDriveEnabledTenant ID: ${SUPERVISION_TENANTID}
Set the sync app update ringEnabledUpdate ring: Production
Silently move Windows known folders to OneDriveEnabled- Desktop: True
- Documents: True
- Pictures: True
- Show notification: No
- Tenant ID: ${SUPERVISION_TENANTID}
Silently sign in users to the OneDrive sync app with their Windows credentialsEnabled
Use OneDrive Files On-DemandEnabled
Warn users who are low on disk spaceEnabledMinimum available disk space: 1024 MB

πŸ‘₯ Group Assignments​

βœ… Included groups:​

  • All Devices

❌ Excluded groups:​

  • πŸ›‘οΈπŸͺŸπŸ’»β›“️ Group | Autopilot Devices - IoT
  • πŸ›‘οΈπŸͺŸπŸ’»β›“️ Group | Autopilot Devices - Kiosk
  • πŸ›‘οΈπŸͺŸπŸ’»β›“️ Group | Autopilot Devices - W365 Boot

Why?
Because those devices don’t use OneDrive. Let’s not force feed sync settings to a Kiosk screen that loops PowerPoint all day.


πŸ’‘ SuperVision Tip​

Some settings ask for a Tenant ID. And while it may be tempting to paste in your own and call it a day… don’t. Seriously.

If you copy-paste your own Tenant ID into a policy that gets deployed to all customers β€” congrats, you just connected every OneDrive client to the wrong cloud. 🚨πŸ’₯

βœ… Use this instead:​

SuperVision will dynamically inject the correct tenant ID for each environment. One tag to rule them all. πŸͺ„


Final Thoughts πŸ˜Œβ€‹

OneDrive is a brilliant tool β€” when used properly. This config makes sure:

  • Users don’t have to think
  • You don’t have to clean up their mess
  • Data is backed up by default

Because trust me, when the CFO deletes their desktop folder, you will get the call. And nobody wants that.


Standardize like a pro.
Configure with intent.
And never trust a folder called Temp.