Microsoft Endpoint Manager – Configuration policies for OneDrive

In the previous blog I introduced configuration policies in Intune. In this blog I want to show you Administrative Templates and how to use them to configure OneDrive for Business.

OneDrive for Business is a standard in most companies for managing and sharing corporate data so I hope this example will be useful for you. An experience with Administrative Templates is almost similar to working with Active Directory GPOs and it’s like creating GPO policy from Intune console.

So lets start. Go to DevicesConfiguration profiles and click Create profile. Choose

PlatformWindows 10 and later

Profile typeTemplates

Template nameAdministrative Template:

Microsoft Endpoint Manager – Configuration policies for OneDrive 01

And press Create. Provide a name for your profile:

Microsoft Endpoint Manager – Configuration policies for OneDrive 02

And click Next.

On the next wizard page in Computer configuration section click on OneDrive:

Microsoft Endpoint Manager – Configuration policies for OneDrive 03

As I mention above it looks very similar to “classic” GPOs:

Microsoft Endpoint Manager – Configuration policies for OneDrive 04

The fFirst setting I want to configure is Use OneDrive Files On-Demand. I want to keep all the files in the cloud instead of synchronizing all of them on every computer I log in. Files I open will be synchronized on-demand. To configure this setting, you can scroll down and go to a second page or you can find this setting by name.

Microsoft Endpoint Manager – Configuration policies for OneDrive 05

Click on the setting and choose Enabled:

Microsoft Endpoint Manager – Configuration policies for OneDrive 06

Again, this experience is very similar to GPO – you see a name of the setting, description and options like Enabled, Disabled or Not Configured. Sometimes you can enable settings and configure some values which I show you later in this blog.

Click OK.

For configuring the next setting we need to have a Tenant ID. Open Azure console, go to Azure Active DirectoryProperties and copy Tenant ID:

Microsoft Endpoint Manager – Configuration policies for OneDrive 07

The next setting I want to configure prevents the user to add OneDrive for Business accounts from other organizations. Click on Allow syncing OneDrive accounts for only specific organizations setting, enable it, paste Tenant ID and click OK:

Microsoft Endpoint Manager – Configuration policies for OneDrive 08

In the similar way I want to configure the next settings:

  • Prevent users from syncing libraries and folders shared from other organizationsDisabled;
  • Prompt users to move Windows known folders to OneDriveDisabled;
  • Require users to confirm large delete operationsDisabled;
  • Prevent users from redirecting their Windows known folders to their PCEnabled;
  • Silently sign in users to the OneDrive sync app with their Windows credentialsEnabled.

I also want to silently redirect known user folders like Desktop, Pictures and Documents from computer to OneDrive. Click on Silently move Windows known folders to OneDrive (2.0) setting, enable it, check your preconfigured Tenant ID and folders you want to redirect, and click OK. In my case I want to notify users when the process successfully finished so I enable Show notifications to users after folders have been redirected as well:

Microsoft Endpoint Manager – Configuration policies for OneDrive 09

The last setting I want to configure is updates for OneDrive. I don’t want to apply new features in a preview mode, but I want to deploy then as soon they are available, so my choice is Production update ring. To enable that open Set the sync app update ring setting and enable it:

Microsoft Endpoint Manager – Configuration policies for OneDrive 10

Then click OK.

You can sort by State and see which settings we have configured:

Microsoft Endpoint Manager – Configuration policies for OneDrive 11

Check it again and then press Next. On the Scope tab page press Next again.

On the Assignments page click Add groups, choose Azure AD security group and click Select:

Microsoft Endpoint Manager – Configuration policies for OneDrive 12

At the end, click Next and Create.

Happy deployment!

Share:

Facebook
Twitter
LinkedIn

Contact Us

On Key

More Posts

Mastering Azure AD Connect - A Comprehensive Guide by WME
Active Directory

Mastering Azure AD Connect – A Comprehensive Guide

Modern businesses are fast moving toward cloud-based infrastructure. In fact, cloud-based business is not just a trend anymore but a strategic necessity. Microsoft’s Azure Active Directory (Azure AD) has become a frontrunner in this domain. It

Read More »
Security Best Practices in SharePoint
Office 365

Security Best Practices in SharePoint

Microsoft SharePoint is an online collaboration platform that integrates with Microsoft Office. You can use it to store, organize, share, and access information online. SharePoint enables collaboration and content management and ultimately allows your teams to

Read More »
The Ultimate Guide to Microsoft Intune - Article by WME
Active Directory

The Ultimate Guide to Microsoft Intune

The corporate world is evolving fast. And with that, mobile devices are spreading everywhere. As we venture into the year 2024, they have already claimed a substantial 55% share of the total corporate device ecosystem. You

Read More »
Protecting Microsoft 365 from on-Premises Attacks
Cloud Security

How to Protect Microsoft 365 from On-Premises Attacks?

Microsoft 365 is diverse enough to enrich the capabilities of many types of private businesses. It complements users, applications, networks, devices, and whatnot. However, Microsoft 365 cybersecurity is often compromised and there are countless ways that

Read More »
Be assured of everything

Get WME Services

Stay ahead of the competition with our Professional IT offerings.