{"id":9610,"date":"2018-04-14T17:20:12","date_gmt":"2018-04-15T00:20:12","guid":{"rendered":"https:\/\/www.zubairalexander.com\/stage\/?p=9610"},"modified":"2019-09-18T19:16:51","modified_gmt":"2019-09-19T02:16:51","slug":"allow-syncing-only-on-pcs-joined-to-specific-domains-in-office-365","status":"publish","type":"post","link":"https:\/\/www.zubairalexander.com\/blog\/allow-syncing-only-on-pcs-joined-to-specific-domains-in-office-365\/","title":{"rendered":"Allow Syncing Only on PCs Joined to Specific Domains in Office 365"},"content":{"rendered":"<p>Microsoft Office 365 has a nice security feature as a syncing option in Office 365 OneDrive admin center called &#8220;Allow Syncing Only on PCs Joined to Specific Domains.&#8221; This feature can be configured by the Office 365 Global Administrator. You will find this option listed in OneDrive admin center under the Sync category. It restricts the syncing of OneDrive content\u00a0to only domain-joined PCs to enhance security.<\/p>\n<p>Here&#8217;s how you can configure this feature.<\/p>\n<ol>\n<li>Logon to Office 365 as a Global Administrator at <a href=\"https:\/\/portal.office.com\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/portal.office.com<\/a>.<\/li>\n<li>Go to the Admin centers and then click <strong>OneDrive<\/strong>.<br \/>\n<a href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-Admin-Center.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9611\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-Admin-Center.png\" alt=\"OneDrive Admin Center\" width=\"258\" height=\"438\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-Admin-Center.png 258w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-Admin-Center-177x300.png 177w\" sizes=\"(max-width: 258px) 100vw, 258px\" \/><\/a><\/li>\n<li>From the Home screen in OneDrive admin center click <strong>Sync<\/strong>.<br \/>\n<a href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-home.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9612\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-home.png\" alt=\"OneDrive home screen\" width=\"712\" height=\"614\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-home.png 712w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-home-300x259.png 300w\" sizes=\"(max-width: 712px) 100vw, 712px\" \/><\/a><\/li>\n<li>You will see the following three options:<br \/>\na)\u00a0Show the Sync button on the OneDrive website<br \/>\nb)\u00a0<strong>Allow syncing only on PCs joined to specific domains<br \/>\n<\/strong>c) Block syncing of specific file types<br \/>\n<a href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-sync-options.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9613\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-sync-options.png\" alt=\"OneDrive sync options\" width=\"784\" height=\"444\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-sync-options.png 784w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-sync-options-300x170.png 300w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-sync-options-768x435.png 768w\" sizes=\"(max-width: 784px) 100vw, 784px\" \/><\/a><\/li>\n<li>The first option is selected by default. Select the second option\u00a0<strong>Allow syncing only on PCs joined to specific domains<\/strong>. This option can restrict syncing of OneDrive data only to computers that have joined your domain.<\/li>\n<li>Click <strong>Edit domains<\/strong> and specify which domains should be allowed syncing of content. Clients who have joined any domains that are not listed here will be prevented from syncing OneDrive data. This seems pretty straight forward, but there is something you should know about this feature. When you click Edit domains, you will see the following box.<br \/>\n<a href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-syncing-to-certain-domains-png.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9614\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-syncing-to-certain-domains-png.png\" alt=\"Enter domain as a GUID\" width=\"271\" height=\"192\" \/><\/a><br \/>\nThis step can be tricky if you don&#8217;t know what you need to do here. Because you are working in Office 365, obviously you are going to enter the domain Globally Unique Identifier (GUID) for your Office 365 domain. Right? Not exactly! You are supposed to enter the domain GUID for your on-premises Active Directory domain here. I know it&#8217;s confusing because there is nothing in the instructions you will find that gives you the impression that this feature only works with on-premises Active Directory.<br \/>\n<span style=\"text-decoration: underline;\">NOTE<\/span>: A GUID is a 128-bit number used to uniquely identify each object in Active Directory. Unlike a Security Identifier (SID), which can potentially change , a GUID never changes and is unique not just across the enterprise, but <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/cc961625.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">according to Microsoft<\/a> it&#8217;s unique across the world.<\/li>\n<li>Run the <strong>Get-ADDomain<\/strong> on your Domain Controller or a member server to get the domain GUID. Look for the <strong>ObjectGUID<\/strong> entry in the results. You can also run Get-ADDomain on your domain-joined workstation if you have the Active Directory PowerShell Module installed, but it&#8217;s much easier to get the domain GUID from your server.<\/li>\n<li>You can add the GUID for additional Active Directory on-premises domains, if necessary. Just remember to press the Enter key after each entry.\u00a0Once you add the GUID and close the <em>Edit domains<\/em> box, you will see your domain GUID(s) added.<a href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-domain-guid-added.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9618\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-domain-guid-added.png\" alt=\"OneDrive sync - domain GUID added\" width=\"784\" height=\"482\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-domain-guid-added.png 784w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-domain-guid-added-300x184.png 300w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/04\/OneDrive-domain-guid-added-768x472.png 768w\" sizes=\"(max-width: 784px) 100vw, 784px\" \/><\/a><\/li>\n<li>Click <strong>Save<\/strong> to keep your changes.<\/li>\n<li>It can take at least an hour before the configuration takes effect and the feature will work.<\/li>\n<\/ol>\n<p>It&#8217;s unfortunate that this feature only works with on-premises Active Directory. There are many small businesses around the world that don&#8217;t have an on-premises Active Directory domain and would therefore be unable to take advantage of this feature. It would be nice if Microsoft adds the words <em>on-premises<\/em> or <em>local<\/em> domain somewhere in the Edit box. For example, updating the instructions and adding the words in bold would be helpful in avoiding confusion:<\/p>\n<table>\n<tbody>\n<tr>\n<td style=\"background-color: #fcfade; text-align: left; vertical-align: top;\"><em><strong>This feature works with on-premises Active Directory domains.<\/strong> Enter each <strong>on-premises<\/strong> domain as a GUID on a new line. <strong>Use the PowerShell command Get-ADDomain on your domain server to get the domain GUID<\/strong><\/em>.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This <a href=\"https:\/\/support.office.com\/en-us\/article\/Allow-syncing-only-on-computers-joined-to-specific-domains-a3b03efd-ccd0-4d3c-b9ae-7f8f3f9485bc?appver=ODB160\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft article<\/a>\u00a0contains a link on how to find the domain GUID, but the information applies to a local on-premises Active Directory. Organizations that don&#8217;t have on-premises Active Directory have difficulty figuring out how to use this article and find their domain GUID. I have provided my feedback to Microsoft. Hopefully, Microsoft will allow us to use this feature with domains in Office 365 in the future, or at least make it clear in the instructions that this OneDrive feature is limited to on-premises domains.<\/p>\n<table>\n<tbody>\n<tr>\n<td style=\"background-color: #e3e3e3; text-align: left;\">Thanks for reading my article. If you are interested in IT training &amp; consulting services, please reach out to me. Visit <a href=\"https:\/\/www.zubairalexander.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">ZubairAlexander.com<\/a> for information on my professional background.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<p><span style=\"font-size: xx-small; font-family: Verdana;\">Copyright \u00a9 2018 <a href=\"https:\/\/www.seattlepro.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">SeattlePro Enterprises, LLC<\/a>. All rights reserved.<br \/>\n<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Office 365 has a nice security feature as a syncing option in Office 365 OneDrive admin center called &#8220;Allow Syncing Only on PCs Joined to Specific Domains.&#8221; This feature can be configured by the Office 365 Global Administrator. You will find this option listed in OneDrive admin center under the Sync category. It restricts [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":11208,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[6,43,67,63,24,11],"tags":[],"class_list":["post-9610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-active-directory","category-articles","category-microsoft-azure","category-office-365","category-security","category-tips-tricks"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2019\/09\/Office365_featured_250x250.png","_links":{"self":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts\/9610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/comments?post=9610"}],"version-history":[{"count":0,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts\/9610\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/media\/11208"}],"wp:attachment":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/media?parent=9610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/categories?post=9610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/tags?post=9610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}