LimitedAccess web-only sensitivity label - guest can still use full Teams client

divadiow 1 Reputation point
2023-02-24T14:41:00.5233333+00:00

Some of our Teams/365/Sharepoint sites have a sensitivity label that only allows for limited web-only access, but external guests in those Teams can still use the desktop client. The app protection seems to be working because they get the yellow banner saying no print, download or whatever.

Here's our setup:

label on team/group/sharepoint siteUser's image

org-level sharepoint unmanaged devices:
User's image

app enforcement CA policy
User's image

no unmanaged device CA policy because we've allowed full access at top level. my understanding it that the site level can have a higher level of restriction, which is what our sensitivity label is setting the site level at. If you do a get-sposite on the sharepoint site with the web-only label you get this output
User's image

which seems correct. "AllowLimitedAccess"

what am I missing? Have I got something the wrong way round? Should the org level be "allow limited, web-only access" and the sensitivity label be less restrictive for site we do want guest users on unmanaged devices to use the full client on?

E3 licensed.

Microsoft Teams
Microsoft Teams
A Microsoft customizable chat-based workspace.
9,034 questions
SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
9,565 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jack 0 Reputation points
    2023-02-26T14:12:30.9866667+00:00

    Hi,

    I think you might need to set the option "allow limited, web only access" for unmanaged devices.

    Guest users typically use unmanaged devices. To prevent them from accessing the site from the desktop the setting must be enabled. To enable it for just a subset of users and not for all users follow the link on the page or this link

    However, regardless if they use the browser or the desktop they cannot download and save files. They can edit them in the app but are not allowed tot save it locally

    Kind regards,

    Jack