question

10434314 avatar image
0 Votes"
10434314 asked 10434314 commented

Conditional Access Block Download Attachment

Hello , I trying for a few days to enable correct a Conditional Access Policy that blocks attachments to download.

I managed to block attachment in owa but still have the option to save it to one drive.

Image

In windows i have the option to save it locally or in OneDrive. In mobile app i have the option to save it to device.

82746-outlook-windows.png

The conditional access policy

82772-policy.png


office-outlook-itprooffice-exchange-online-itprooffice-exchange-server-mailflowoffice-onedrive-client-itpro
owa.png (7.3 KiB)
outlook-windows.png (10.5 KiB)
policy.png (76.1 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndyDavid avatar image
0 Votes"
AndyDavid answered

You need to enable this on the Sharepoint side which will create the Conditional Access policy
https://docs.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

10434314 avatar image
0 Votes"
10434314 answered AndyDavid commented

ok that solved the problem in owa but in device still have the option to download it and in outlook windows too.
82734-device.jpg


82736-image-2021-03-30-154142.png



device.jpg (69.4 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

What Policy is set on the Exchange Online Side?

0 Votes 0 ·
KyleXu-MSFT avatar image
0 Votes"
KyleXu-MSFT answered

@10434314

Try to use “Set-ActiveSyncMailboxPolicy” command to block attachment from downloading:
82935-qa-kyle-09-52-28.png


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

10434314 avatar image
0 Votes"
10434314 answered 10434314 edited

Hello and thank you for your answers!!!

I have already done this procedure.83279-image-2021-03-31-141558.png

Ok maybe i don't ask the right questions... now I'm confused.
the question is what is the right procedure to block attachments from any device (web, windows app, mobile app ) ?

Thank you again.



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndyDavid avatar image
0 Votes"
AndyDavid answered

Hi, thats not the correct setting if using Conditional Access.

If you want to block using OWA, follow:
https://petri.com/conditional-access-blocks-office-365-downloads

If you want block on mobile devices, look at Cloud App Security:
https://docs.microsoft.com/en-us/cloud-app-security/use-case-proxy-block-session-aad

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

10434314 avatar image
0 Votes"
10434314 answered

Hello in mobile devices and outlook in windows still cannot block attachment only.
I created an access and session policy just to be sure but with the same results 83450-image-2021-04-01-101744.png83478-cloud-app.png



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

KyleXu-MSFT avatar image
0 Votes"
KyleXu-MSFT answered

@10434314

If so, why not use transport rule to block email which contains attachment directly:
83614-qa-kyle-16-36-48.png


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

10434314 avatar image
0 Votes"
10434314 answered KyleXu-MSFT commented

Yes but the user hasn't the opportunity to view the attachment. I want the users to preview their files but not download them from anywhere.
84002-pic.png


pic.png (23.4 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

In this situation, I would suggest you confirm with AAD forum. Whether could manage all devices with a Azure device policy.

Here are information about which could done in Exchange online side: Read Only And Attachment Download Restrictions in Exchange Online

0 Votes 0 ·
10434314 avatar image
0 Votes"
10434314 answered 10434314 commented

Hello I created a ticket in Microsoft. They told me that in outlook windows application cannot be managed via cloud service the only thing it can be done is from registry to block attachments. So for the Outlook mobile does not use ActiveSync anymore and many of the restrictions doesn't work.

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

So, we can only limit the OWA or block email which contains attachment.

0 Votes 0 ·

correct only in OWA

0 Votes 0 ·