Reader small image

You're reading from  Microsoft Office 365 Administration Cookbook

Product typeBook
Published inSep 2020
PublisherPackt
ISBN-139781838551230
Edition1st Edition
Right arrow
Author (1)
Nate Chamberlain
Nate Chamberlain
author image
Nate Chamberlain

Nate Chamberlain is a technical content creator, solution architect, and trainer, recognized as a 5-year Microsoft MVP. With a background in business analysis and systems administration, Nate has authored seven books and manages his blog. He holds an array of certifications, including M365 Enterprise Administrator Expert and Microsoft Power Platform App Maker Associate, and is a frequent speaker at user groups and conferences.
Read more about Nate Chamberlain

Right arrow

Chapter 6: Administering OneDrive


OneDrive is Office 365 (O365)'s solution for individual users' storage space. While SharePoint is best for team file collaboration, OneDrive provides personal storage and enables productivity on a personal level. In this chapter, we will dive into important settings that enable users to remain productive and creative while still operating within secure boundaries set by administrators. We will manage the default settings and take a look at migrating data from local network locations to OneDrive.

In this chapter, we'll cover the following OneDrive recipes:

  • Enabling the local syncing of files
  • Restricting local syncing to PCs on specific domains
  • Setting up compliance safeguards
  • Providing manager access to a terminated employee's OneDrive
  • Setting the default share link type
  • Configuring external sharing permission levels
  • Restricting sharing to specific domains
  • Adjusting all users' default...

Technical requirements

You'll need to be a SharePoint or global admin to complete the recipes in this chapter.

Enabling the local syncing of files

This recipe will demonstrate how you can allow/disallow the syncing of OneDrive files from online to local machines. Note that this affects SharePoint sync abilities as well.

Getting ready

You must be a global or SharePoint administrator to access the OneDrive admin center.

How to do it…

  1. Go to https://admin.onedrive.com.
  2. Select Sync from the left-side navigation menu:

    Figure 6.1 – The Sync option in the left-hand navigation menu of the OneDrive admin center

  3. Choose how you want users to be able to sync files from your organization by checking/unchecking the first box, labeled Show the Sync button on the OneDrive website:

    Figure 6.2 – Option to show the Sync button for OneDrive enabled

  4. Click Save.

How it works…

You've just ensured users will see the Sync button on their OneDrive sites. Once you've made sure that the Sync button is visible for users (and device management...

Restricting local syncing to PCs on specific domains

In this recipe, we'll get more granular and make sure only users attempting to sync their OneDrive from specific domain addresses can do so. Note that this affects SharePoint sync abilities as well.

Getting ready

You must be a global or SharePoint administrator to access the OneDrive admin center.

How to do it…

  1. Go to https://admin.onedrive.com.
  2. Select Sync from the left-side navigation menu:

    Figure 6.3 – The Sync option in the left-hand navigation menu of the OneDrive admin center

  3. Check the second checkbox, labeled Allow syncing only on PCs joined to specific domains. Enter the GUIDs for allowed domains in the box that appears (one per line, as directed):

    Figure 6.4 – The Sync option for allowing syncing on devices joined to specific domains

  4. Click Save.

How it works…

In this recipe, you configured the sync settings in the OneDrive admin center to only allow syncing...

Setting up compliance safeguards

Compliance is a deep and important topic that can't be covered fully in a single recipe. In this recipe, we'll simply cover accessing compliance settings and ideas relating to OneDrive specifically. Check out the final three chapters of the book for more general O365 security and compliance recipes.

Getting ready

You should be a SharePoint or global admin, and in some cases, you may need additional permissions depending on what specific compliance tasks you'd like to complete.

How to do it…

  1. Go to the OneDrive admin center at https://admin.onedrive.com.
  2. Click on Compliance in the left-side navigation menu.
  3. Review all of the OneDrive compliance activities you can perform, shown in the following screenshot, noting that all of them will redirect you to the O365 Security & Compliance Center (https://protection.office.com):

Figure 6.5 – Compliance settings linked in the OneDrive...

Providing manager access to a terminated employee's OneDrive

After an employee leaves your organization, their OneDrive is scheduled for deletion. Before it's gone, it's common to provide that employee's manager with access to their OneDrive in case there are business-critical documents or resources there that need to be relocated for others to use. In this recipe, you'll learn how to provide managers with access to their former employees' OneDrive sites.

Getting ready

You must be a global or SharePoint administrator to complete these steps within the SharePoint admin center.

How to do it…

  1. Go to the SharePoint admin center at https://YOURTENANT-admin.sharepoint.com.
  2. Select More features from the left-side navigation menu:

    Figure 6.6 – The More features option in the SharePoint admin center's left-hand navigation menu

  3. Under User profiles, click the Open button:

    Figure 6.7 – The Open button to access the User...

Configuring external sharing permission levels

External sharing in OneDrive (and SharePoint) allows your users to open access to specific documents and content to users outside your organization's directory. As an admin, you can control the level to which this is possible, including blocking anonymous sharing or requiring that the external user be added to the organization's directory before they can access the content.

In this recipe, we'll go through the steps to review and adjust the OneDrive external sharing settings from the OneDrive admin center.

Getting ready

You must be a global or SharePoint administrator to access the OneDrive admin center.

How to do it…

  1. Go to the OneDrive admin center at https://admin.onedrive.com.
  2. Select Sharing from the left-side navigation menu.
  3. Scroll down to the External sharing section.
  4. Slide the OneDrive slider to the desired level of allowed external sharing that you want to set, as shown in the...

Restricting sharing to specific domains

In the previous recipe, we covered how to configure external sharing abilities within OneDrive and SharePoint. Part of doing so is considering the restriction of external sharing to people on specific domains. For example, you may wish to block users in your organization from sharing files with your top competitors' domain, or you may wish to only allow sharing with brand domains that fall under a parent company umbrella.

In this recipe, we'll cover how to restrict external sharing to specific domains we trust and know our users need to collaborate with regularly.

Getting ready

You must be a global or SharePoint administrator to access the OneDrive admin center.

How to do it…

  1. Go to the OneDrive admin center at https://admin.onedrive.com.
  2. Select Sharing from the left-side navigation menu.
  3. Scroll down to the External sharing section.
  4. Expand Advanced settings for external sharing.
  5. Check the...

Adjusting all users' default storage allocation and retention periods

In this recipe, we'll cover a simple but important setting in the OneDrive admin center that allows setting the default storage limit for individual users' OneDrive sites, as well as the retention period for which those sites should be kept after the associated user is marked for deletion.

Getting ready

You must be a global or SharePoint administrator to access the OneDrive admin center.

How to do it…

  1. Go to the OneDrive admin center at https://admin.onedrive.com.
  2. Select Storage from the left-side navigation menu.
  3. Enter a number (in/GB) in the Default storage in GB box that represents the maximum amount all users can save in their OneDrive site. Then, enter a number (in days) in the Days to retain files in OneDrive after a user account is marked for deletion box that represents how long files will be kept once their associated owner is marked for deletion:

    Figure 6.16...

Restricting OneDrive access to devices on specific IP address locations

Depending on your organization's industry and compliance requirements, it may be helpful to know how you can restrict OneDrive access to only those devices connecting from approved IP addresses. In this recipe, we'll specify the IP addresses from which we'll allow connections to OneDrive.

Getting ready

You must be a global or SharePoint administrator to access the OneDrive admin center.

How to do it…

  1. Go to the OneDrive admin center at https://admin.onedrive.com.
  2. Select Device access from the left-side navigation menu.
  3. Check the box for Allow access only from specific IP address locations.
  4. Enter the IP addresses, one per line, from which connected devices should be able to access OneDrive:

    Figure 6.17 – Allowed IP addresses configuration

  5. Click Save.

How it works…

Once you've saved the list of approved IP addresses, users will receive...

Configuring mobile app permissions

You can control how users interact with organizational data via the OneDrive and SharePoint mobile apps. For example, you may wish to prevent users from taking screenshots, copying and pasting organizational data, downloading files to their device storage, or more. In this recipe, we'll specify those restrictions as a policy in the OneDrive admin center.

Getting ready

You must be a global or SharePoint administrator to access the OneDrive admin center.

How to do it…

  1. Go to the OneDrive admin center at https://admin.onedrive.com.
  2. Select Device access from the left-side navigation menu.
  3. Scroll down to the Mobile application management section.
  4. Check the boxes for any settings that help users adhere to the compliance and security policies deployed by your organization:

    Figure 6.18 – Mobile app permissions policy settings

  5. Specify a time limit after which user access should be reverified, and at which point...

Migrating data using the SharePoint Migration Tool

You can use the SharePoint Migration Tool to migrate content from your network or local file shares to OneDrive. In this recipe, we'll do just that, migrating content from a local file to our OneDrive.

Getting ready

  • You must be a global administrator to perform migrations, or at least have appropriate permissions to both source and destination sites.
  • You must download and install the SharePoint Migration Tool at https://aka.ms/spmt-ga-page.

How to do it…

  1. Launch the SharePoint Migration Tool and sign in to your O365 tenant when prompted.
  2. If you haven't used the tool before, select Start your first migration. Otherwise, choose Start new migration.
  3. Select File Share for this recipe. Note you could also prepare a CSV file to map bulk sources and destinations for bulk migration.
  4. Click Choose folder.
  5. Select a folder and click Next:

    Figure 6.20 – File share location...

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Microsoft Office 365 Administration Cookbook
Published in: Sep 2020Publisher: PacktISBN-13: 9781838551230
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Author (1)

author image
Nate Chamberlain

Nate Chamberlain is a technical content creator, solution architect, and trainer, recognized as a 5-year Microsoft MVP. With a background in business analysis and systems administration, Nate has authored seven books and manages his blog. He holds an array of certifications, including M365 Enterprise Administrator Expert and Microsoft Power Platform App Maker Associate, and is a frequent speaker at user groups and conferences.
Read more about Nate Chamberlain