67.3 (L2) Ensure 'Disable One Drive File Sync' is set to 'Sync Disabled'

Information

This policy setting lets you prevent apps and features from working with files on OneDrive using the Next Generation Sync Client.

The recommended state for this setting is: Sync Disabled

Enabling this setting prevents users from accidentally (or intentionally) uploading confidential or sensitive corporate information to the OneDrive cloud service using the Next Generation Sync Client.

Note: This security concern applies to

any

cloud-based file storage application installed on a workstation, not just the one supplied with Windows.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Sync Disabled :

System\Disable One Drive File Sync

Impact:

Users can't access OneDrive from the OneDrive app and file picker. Windows Store apps can't access OneDrive using the WinRT API. OneDrive doesn't appear in the navigation pane in File Explorer. OneDrive files aren't kept in sync with the cloud. Users can't automatically upload photos and videos from the camera roll folder.

Note: If your organization uses Microsoft 365, be aware that this setting will prevent users from saving files to OneDrive/SkyDrive.

-

Allow syncing OneDrive accounts for only specific organizations

- a computer-based setting that restricts OneDrive client connections to only approved tenant IDs.
-

Prevent users from synchronizing personal OneDrive accounts

- a user-based setting that prevents use of consumer OneDrive (i.e. non-business).

See Also

https://workbench.cisecurity.org/benchmarks/16852

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|13.4

Plugin: Windows

Control ID: 67dae0298554521bff1a71fc105f8760e3c713328f08663c63954d6c3c524752