Office 365 access to OneDrive for Business accounts and block consumer accounts
15013
Created On 03/27/19 22:40 PM - Last Modified 12/06/22 13:30 PM
Symptom
-
User tries to access OneNote via web access to Office365 cloud.
-
Unable to access OneNote in cloud, when tried to access from both consumer account and enterprise account.
Environment
- PANOS 7.x/8.x with dynamic updates for apps/threats up-to-date [any version later than 597].
- Decryption is not used for this traffic ingressing or egressing the Firewall.
Cause
Even though there are policies for consumer and enterprise access, AppID 'OneDrive' is not specifically included with any security rule
Resolution
Specifically Allowing OneDrive AppID in the security policy would resolve access issue to Onenote in cloud.
However, consumer users will be able to access enterprise version of OneNote which is not desired by the enterprise.
- Create a URL filtering profile with URL-category 'online-storage-and-backup'
- Set site Access "block" for this category
- Use this URL-filtering-profile with the same security rule that is allowing OneDrive.
Reference:
FAQ - Office 365 Access Control