OneDrive Personal Sync Prevention
Audience: Platform Engineering, security administrators
Purpose: Prevent personal OneDrive account sync to mitigate data exfiltration risk
Overview
This procedure prevents Microsoft from automatically syncing detected personal OneDrive accounts on University-managed Windows devices (Microsoft 365 Roadmap ID 490064). Implementation mitigates data exfiltration risk and ensures corporate data remains within controlled environments.
Key Policies
| Policy | Purpose | Effect |
|---|---|---|
| DisableNewAccountDetection | Suppresses prompts to sync personal accounts | Recommended minimal impact |
| DisablePersonalSync | Blocks personal account synchronization | Optional - strict control |
| AllowTenantList | Restricts sync to specified tenant IDs | Optional - tenant enforcement |
Use DisableNewAccountDetection for minimal user impact. Add DisablePersonalSync or AllowTenantList only if stricter controls are required.
Prerequisites
| Requirement | Details |
|---|---|
| GPO Knowledge | Active Directory Group Policy Management |
| Intune Access | Microsoft Intune admin center |
| Admin Privileges | GPO and/or Intune configuration rights |
| Tenant ID | Your Microsoft 365 Tenant ID |
Configuration via Intune
Option A: Suppress Prompt (Recommended)
Hides the prompt to sync personal accounts without blocking manual addition.
- Navigate to Devices → Windows → Configuration profiles
- Click + Create profile
- Platform: Windows 10 and later
- Profile type: Templates → Custom
- Add OMA-URI setting:
| Setting | Value |
|---|---|
| Name | Suppress OneDrive Personal Account Prompt |
| OMA-URI | ./Device/Vendor/MSFT/Policy/Config/OneDrive~Policy~OneDriveNGSC/DisableNewAccountDetection |
| Data type | Integer |
| Value | 1 |
- Assign to Windows device groups
- Click Create
Result: Users won't see prompts to add personal accounts but can still add manually if desired.
Option B: Strict Prevention (Settings Catalog)
For stricter control, use the Settings Catalog:
- Navigate to Devices → Windows → Configuration profiles
- Click + Create profile
- Platform: Windows 10 and later
- Profile type: Settings catalog
- Add settings as needed:
Prevent Personal Sync:
- Path:
Administrative Templates > OneDrive - Setting: "Prevent users from syncing personal OneDrive accounts (User)"
- Effect: Blocks all personal accounts
Tenant Allow List:
- Path:
Administrative Templates > OneDrive - Setting: "Allow syncing OneDrive accounts for only specific organizations (Device)"
- Effect: Only allows specified tenant IDs
- Configure and assign to device groups
Configuration via Group Policy
Step 1: Update ADMX Templates
- Locate OneDrive templates:
- Per-user:
%localappdata%\Microsoft\OneDrive\[BuildNumber]\adm\ - Per-machine:
%ProgramFiles%\Microsoft OneDrive\[BuildNumber]\adm\
- Per-user:
- Copy
OneDrive.admxto central store:\\domain\SYSVOL\domain\Policies\PolicyDefinitions
- Copy
OneDrive.admlto language folder:\\domain\SYSVOL\domain\Policies\PolicyDefinitions\en-us
Step 2: Configure Policies
Open Group Policy Management (gpmc.msc) and edit your GPO:
Hide Personal Sync Messages (Recommended):
- Path:
Computer Configuration > Administrative Templates > OneDrive - Setting: "Hide the messages to sync Consumer OneDrive files"
- Value: Enabled
Prevent Personal Sync (Optional):
- Path:
User Configuration > Administrative Templates > OneDrive - Setting: "Prevent users from syncing personal OneDrive accounts"
- Value: Enabled
Tenant Allow List (Optional):
- Path:
Computer Configuration > Administrative Templates > OneDrive - Setting: "Allow syncing OneDrive accounts for only specific organizations"
- Value: Enabled, add your Tenant ID(s)
Step 3: Apply and Verify
- Run
gpupdate /forceon test device - Restart OneDrive sync client or reboot
- Attempt to add a personal account to verify blocking
Verification
| Test | Expected Result |
|---|---|
| Personal account prompt | Should not appear (DisableNewAccountDetection) |
| Manual personal account add | Should fail (if DisablePersonalSync enabled) |
| Corporate account sync | Should work normally |
| Tenant-restricted sync | Only allowed tenant IDs work (if AllowTenantList enabled) |
Related Resources
- Intune Documentation — Endpoint management
- Scope Groups & Naming — Policy assignment groups
- Microsoft OneDrive Admin — Official documentation