However, some organizations want to block access to SharePoint files upload, download, view, edit, create yet allow their employees to use Teams desktop, mobile, and web clients on unmanaged devices. This article explains how you can work around this limitation and allow your employees to continue using Teams while completely blocking access to files stored in SharePoint. Blocking or limiting access on unmanaged devices relies on Azure AD conditional access policies.
Learn about Azure AD licensing. For info about recommended SharePoint Online access policies, see Policy recommendations for securing SharePoint sites and files. Search related threads. Remove From My Forums. Asked by:. Archived Forums. Group Policy.
Sign in to vote. Dear Support, Please guide us to restrict user to save files to desktop,documents and other folder through group policy. Regards, Itsupport. Tuesday, July 16, AM. For this reason, we also highly recommend creating a restore point before making any of the changes here. Standard warning: Registry Editor is a powerful tool and misusing it can render your system unstable or even inoperable.
And definitely back up the Registry and your computer! Name the new value DisallowRun. Double-click the new DisallowRun value to open its properties dialog. Name the new key DisallowRun , just like the value you already created. If you want to edit the list of blocked apps, just return to the DisallowRun key and make the changes you want. If you want to restore access to all apps, you can either delete the whole Explorer key you created—along with DisallowRun subkey and all the values.
Or you could just go back and change the value of the DisallowRun value you created from 1 back to 0, effectively turning off app blocking while leaving the list of apps in place should you want to turn it on again in the future. Restricting users to running only certain apps in the Registry follows almost exactly the same procedure as blocking specific apps. Fire up Registry Editor and then head to the following key:. Name the new value RestrictRun.
Double-click the new RestrictRun value to open its properties dialog. Name the new key RestrictRun , just like the value you already created. Create a new string value inside the RestrictRun key for each app you want to block. You should only be able to run apps to which you explicitly allowed access. To reverse your changes, you can delete the Explorer key you created along with the RestrictRun subkey and all values or you can set that RestrictRun value you created back to 0, turning off restricted access.
If you use the Pro or Enterprise version of Windows, blocking or restricting apps can be a little easier because you can use the Local Group Policy Editor to do the job. That is it. You can now close the application. From now on, anyone who tries to open the blocked application will see error messages like below. When you want to access the blocked application, uncheck the checkbox next to the list item and restart explorer as shown in step 6. As you can see, it is pretty easy to block users from accessing or opening an application in Windows.
Sharing files, folders, and list items in OneDrive. OneDrive work or school More Notes: This feature is available for OneDrive for work or school and may be turned off for your account. Need more help? Expand your skills. Get new features first. Was this information helpful?
0コメント