cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
DenisMolodtsov
Kudo Kingpin
Kudo Kingpin

Disable "Create share link" action or the entiore "OneDrive for Business connector"

We are trying to figure out how to disable/block OneDrive for business connector completely or the "Create Share link" actions. Is it possible? On the photo below, you can see that at some M365 tenant it was possible to block this action somehow. The only issue is that the user who took this photo is not my colleague and they have no idea how it was set up. Basically, we are trying to disable this feature in our organization:

 

Photo.jpg

From what I can see we can't block OOB connectors such as OneDrive for Business:

 

!!!.jpg

Sharing capabilities are disabled at the Tenant level

- Sharing capabilities and anonymous links are completely disabled on the Tenant level and on OneDrive sites level. SharingCapability : Disabled

 

Any help will be greatly appreciated!

12 REPLIES 12
ScottShearer
Super User
Super User

@DenisMolodtsov 

Have you verified that the link that is created actually works as expected?  

If I have answered your question, please mark your post as Solved.
If you like my response, please give it a Thumbs Up.

Scott

hi @ScottShearer. Well, the expected behaviour for the link is not to work. The problem is that:

- While the tenant has the most restrictive policies possible, I can create the link and it works. The generated link contains a pre-authenticated WJT token which is good for one hour. It meas tenants affected by this issue cannot prevent users from creating these links.

- The produced link can be opened from an unmanaged device without a credentials priompt.

jinivthakkar
Community Champion
Community Champion

@DenisMolodtsov I have seen your other post also I was able to reproduce the issue on my tenant as well

VictorIvanidze
Community Champion
Community Champion

Hi @DenisMolodtsov,

 

it's just a shot in the dark, but anyway: can you filter/block already created links in the already existing emails instead of preventing their creation? 


@VictorIvanidze wrote:

Hi @DenisMolodtsov,

 

it's just a shot in the dark, but anyway: can you filter/block already created links in the already existing emails instead of preventing their creation? 



Do you know where would I find a repository of these pre-authenticated links? Do you think it might be possible via API? 

 

When I go to the file's Manage Access, the panel says that there are no links giving access. But I know for a fact that there are "preauthenticated" links. These links just don't show up here for some reason:

DenisMolodtsov_1-1623331474152.png

 

 


@jinivthakkar wrote:

@DenisMolodtsov I have seen your other post also I was able to reproduce the issue on my tenant as well


Thank you for checking! I am glad a few other people were able to verify this issue independently. 

jinivthakkar
Community Champion
Community Champion

@DenisMolodtsov get sharing report

 

To run the report (OneDrive)

  1. From the Microsoft 365 app launcher, select the OneDrive tile.
  2. On the Settings menu, click OneDrive settings.
  3. Click More settings, and then click Run sharing report.
  4. Choose a location to save the report, and then click Save.

Link - https://docs.microsoft.com/en-us/sharepoint/sharing-reports

 

--------------------------------------------------------------------------------
If this post helps answer your question, please click on “Accept as Solution” to help other members find it more quickly. If you thought this post was helpful, please give it a Thumbs Up.

Thank you for the suggestion. Unfortunately, this report does not list any of these "pre-authenticated" links. This is despite the fact that I can see that these links are working:

 

Shared links reportpng.png

jinivthakkar
Community Champion
Community Champion

@DamoBird365 Hi Damien, can you please help on this ?

Hi @DenisMolodtsov 

 

I've not got time to test the scenarios at the moment but have you explored here:

 

DamoBird365_0-1623398057059.png

 

Not sure if flow honours these settings (you would hope) but you could implement a security group in AAD and then choose the type of sharing that you allow (authenitcated guests or anyone).

 

I saw a discussion about OneDrive sharing here https://onedrive.uservoice.com/forums/913531-onedrive-sharing-collaboration/suggestions/17715682-dis... and one suggestion is DLP - for which I don't have the necessary experience of I am afraid.

 

If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
Cheers,
Damien


P.S. take a look at my new blog here and like & subscribe to my YouTube Channel thanks 😉

jinivthakkar
Community Champion
Community Champion

@DamoBird365 thanks Damien, even I have very less experience in DLP but I had tried creating a DLP but even then it did not block the anonymous link creation(may be I did not create DLP correctly)

 

Thank you,  @DamoBird365. I want to add more information for the context.

 

Least permissive policy

External sharing settings are not applicable when we choose the "least permissive" sharing policies. Notice how the "More external sharing settings" is greyed out:

DenisMolodtsov_0-1623450228970.png

 

We can verify that it is impossible to generate the anonymous links via the user interface: 

DenisMolodtsov_1-1623450251275.png

 

 

 

Blocking sharing altogether

https://onedrive.uservoice.com/forums/913531-onedrive-sharing-collaboration/suggestions/17715682-dis... <- this suggestion is about blocking sharing altogether. This is not quite what we are trying to do. We merely want Power Automate/OneDrive to respect the tenant settings that prohibit Anonymous links. Looks like the Power Automate OneDrive for business connector somehow bypasses all restrictions and just creates these "pre-authenticated links" that work no matter what. 

 

 

Blocking OneDrive for business connector and DLP

The DLP policies don't allow blocking certain connectors like Teams, Outlook, SharePoint and OneDrive for business:

DenisMolodtsov_2-1623450391563.png

 

Pre-authenticated links vs Anonymous links

As one Microsoft representative pointed out, the Anonymous links is not the same as "pre-authenticated" links. The latter work only for 1 hour and contain a JWT token that will let you download a document using. However, it does not make sense to have the least permissive sharing policy while you can easily bypass it by using Power Automate "Share a file" action.

 

 

Replication steps

- Make sure the tenant has the "Least permissive" sharing policy

- Create a flow with a single "Create share link" ation

- Run the flow

- Try opening the resulting string from a different browser/computer/device :

 

DenisMolodtsov_3-1623450459359.png

 

Note that there was at least one person who was not able to reproduce this issue. He is a Tenant admin and he has no idea what he did to fix this issue. 

 

Helpful resources

Announcements

Power Platform Connections - Episode 7 | March 30, 2023

Episode Seven of Power Platform Connections sees David Warner and Hugo Bernier talk to Microsoft MVP Dian Taylor, alongside the latest news, product reviews, and community blogs.     Use the hashtag #PowerPlatformConnects on social media for a chance to have your work featured on the show!      Show schedule in this episode:    0:00 Cold Open 00:30 Show Intro 01:02 Dian Taylor Interview 18:03 Blogs & Articles 26:55 Outro & Bloopers    Check out the blogs and articles featured in this week’s episode:    https://francomusso.com/create-a-drag-and-drop-experience-to-upload-case-attachments @crmbizcoach https://www.youtube.com/watch?v=G3522H834Ro​/  @pranavkhuranauk https://github.com/pnp/powerapps-designtoolkit/tree/main/materialdesign%20components @MMe2K​ https://2die4it.com/2023/03/27/populate-a-dynamic-microsoft-word-template-in-power-automate-flow/ @StefanS365 https://d365goddess.com/viva-sales-administrator-settings/ @D365Goddess https://marketplace.visualstudio.com/items?itemName=megel.mme2k-powerapps-helper#Visualize_Dataverse_Environments @MMe2K    Action requested:  Feel free to provide feedback on how we can make our community more inclusive and diverse.    This episode premiered live on our YouTube at 12pm PST on Thursday 30th March 2023.    Video series available at Power Platform Community YouTube channel.    Upcoming events:  Business Applications Launch – April 4th – Free and Virtual! M365 Conference - May 1-5th - Las Vegas Power Apps Developers Summit – May 19-20th - London European Power Platform conference – Jun. 20-22nd - Dublin Microsoft Power Platform Conference – Oct. 3-5th - Las Vegas    Join our Communities:  Power Apps Community Power Automate Community Power Virtual Agents Community Power Pages Community    If you’d like to hear from a specific community member in an upcoming recording and/or have specific questions for the Power Platform Connections team, please let us know. We will do our best to address all your requests or questions.       

Announcing | Super Users - 2023 Season 1

Super Users – 2023 Season 1    We are excited to kick off the Power Users Super User Program for 2023 - Season 1.  The Power Platform Super Users have done an amazing job in keeping the Power Platform communities helpful, accurate and responsive. We would like to send these amazing folks a big THANK YOU for their efforts.      Super User Season 1 | Contributions July 1, 2022 – December 31, 2022  Super User Season 2 | Contributions January 1, 2023 – June 30, 2023    Curious what a Super User is? Super Users are especially active community members who are eager to help others with their community questions. There are 2 Super User seasons in a year, and we monitor the community for new potential Super Users at the end of each season. Super Users are recognized in the community with both a rank name and icon next to their username, and a seasonal badge on their profile.  Power Apps  Power Automate  Power Virtual Agents  Power Pages  Pstork1*  Pstork1*  Pstork1*  OliverRodrigues  BCBuizer  Expiscornovus*  Expiscornovus*  ragavanrajan  AhmedSalih  grantjenkins  renatoromao    Mira_Ghaly*  Mira_Ghaly*      Sundeep_Malik*  Sundeep_Malik*      SudeepGhatakNZ*  SudeepGhatakNZ*      StretchFredrik*  StretchFredrik*      365-Assist*  365-Assist*      cha_cha  ekarim2020      timl  Hardesh15      iAm_ManCat  annajhaveri      SebS  Rhiassuring      LaurensM  abm      TheRobRush  Ankesh_49      WiZey  lbendlin      Nogueira1306  Kaif_Siddique      victorcp  RobElliott      dpoggemann  srduval      SBax  CFernandes      Roverandom  schwibach      Akser  CraigStewart      PowerRanger  MichaelAnnis      subsguts  David_MA      EricRegnier  edgonzales      zmansuri  GeorgiosG      ChrisPiasecki  ryule      AmDev  fchopo      phipps0218  tom_riha      theapurva  takolota     Akash17  momlo     BCLS776  Shuvam-rpa     rampprakash  ScottShearer     Rusk  ChristianAbata     cchannon  Koen5     a33ik  Heartholme     AaronKnox  okeks      Matren   David_MA     Alex_10        Jeff_Thorpe        poweractivate        Ramole        DianaBirkelbach        DavidZoon        AJ_Z        PriyankaGeethik        BrianS        StalinPonnusamy        HamidBee        CNT        Anonymous_Hippo        Anchov        KeithAtherton        alaabitar        Tolu_Victor        KRider        sperry1625        IPC_ahaas      zuurg    rubin_boer   cwebb365   Dorrinda   G1124   Gabibalaban   Manan-Malhotra   jcfDaniel   WarrenBelz   Waegemma   drrickryp   GuidoPreite    If an * is at the end of a user's name this means they are a Multi Super User, in more than one community. Please note this is not the final list, as we are pending a few acceptances.  Once they are received the list will be updated. 

Register now for the Business Applications Launch Event | Tuesday, April 4, 2023

Join us for an in-depth look into the latest updates across Microsoft Dynamics 365 and Microsoft Power Platform that are helping businesses overcome their biggest challenges today.   Find out about new features, capabilities, and best practices for connecting data to deliver exceptional customer experiences, collaborating, and creating using AI-powered capabilities, driving productivity with automation—and building towards future growth with today’s leading technology.   Microsoft leaders and experts will guide you through the full 2023 release wave 1 and how these advancements will help you: Expand visibility, reduce time, and enhance creativity in your departments and teams with unified, AI-powered capabilities.Empower your employees to focus on revenue-generating tasks while automating repetitive tasks.Connect people, data, and processes across your organization with modern collaboration tools.Innovate without limits using the latest in low-code development, including new GPT-powered capabilities.    Click Here to Register Today!    

Check out the new Power Platform Communities Front Door Experience!

We are excited to share the ‘Power Platform Communities Front Door’ experience with you!   Front Door brings together content from all the Power Platform communities into a single place for our community members, customers and low-code, no-code enthusiasts to learn, share and engage with peers, advocates, community program managers and our product team members. There are a host of features and new capabilities now available on Power Platform Communities Front Door to make content more discoverable for all power product community users which includes ForumsUser GroupsEventsCommunity highlightsCommunity by numbersLinks to all communities Users can see top discussions from across all the Power Platform communities and easily navigate to the latest or trending posts for further interaction. Additionally, they can filter to individual products as well.   Users can filter and browse the user group events from all power platform products with feature parity to existing community user group experience and added filtering capabilities.     Users can now explore user groups on the Power Platform Front Door landing page with capability to view all products in Power Platform.      Explore Power Platform Communities Front Door today. Visit Power Platform Community Front door to easily navigate to the different product communities, view a roll up of user groups, events and forums.

Microsoft Power Platform Conference | Registration Open | Oct. 3-5 2023

We are so excited to see you for the Microsoft Power Platform Conference in Las Vegas October 3-5 2023! But first, let's take a look back at some fun moments and the best community in tech from MPPC 2022 in Orlando, Florida.   Featuring guest speakers such as Charles Lamanna, Heather Cook, Julie Strauss, Nirav Shah, Ryan Cunningham, Sangya Singh, Stephen Siciliano, Hugo Bernier and many more.   Register today: https://www.powerplatformconf.com/   

Users online (3,660)