Microsoft OneDrive: New policies to control file exclusions

🚨 The Signal: OneDrive will allow users to manage file exclusions by default, potentially bypassing security policies. New policies enable administrators to disable user control and override Microsoft's default exclusion list, maintaining data sync integrity and security posture.

The Impact

Admins and Security Teams are affected by new user-managed OneDrive file exclusions, creating a risk of unapproved data syncs or exfiltration.

  • Security Teams: Risk of unapproved file types syncing or being excluded, bypassing data loss prevention.
  • Admins: Need to implement new policies to control user exclusion capabilities.
  • End Users: Gain new self-service control over file exclusions, potentially leading to unintended data exposure.
  • Compliance Officers: Potential for non-compliant data to be synced or excluded, impacting audit trails.

The Action

  1. Review current OneDrive sync policies for file exclusions.
  2. Implement 'DisableChangesToODIgnoreList' policy to prevent users from managing exclusions, if required.
  3. Implement 'DisableDefaultODIgnoreList' policy if Microsoft's default exclusions conflict with organizational requirements.
  4. Communicate changes to users regarding file exclusion management.
  5. Monitor OneDrive sync activity for compliance with data governance policies.

Impact: high · Workload: OneDrive · Essential Eight: Application Control, User Application Hardening · ISM: ISM-0843, ISM-1412, ISM-1485, ISM-1486, ISM-1490, ISM-1542, ISM-1544, ISM-1582, ISM-1585, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1823, ISM-1824, ISM-1859, ISM-1860, ISM-1870, ISM-1871