Sharepoint online and Conditional access

Jay Singh 1 Reputation point
2020-10-28T23:08:26.873+00:00

I have conditional access applied to SharePoint online which only allows browser based access from unmanaged devices.
When I invite a guest user to access my SPO site what can they do.

According to me:
They can view and edit document (if edit rights are provided)
They cannot download or upload a document.

Please let me know what you think.

SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
10,810 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Allen Xu_MSFT 13,831 Reputation points
    2020-10-29T10:11:45.973+00:00

    Hi @Jay Singh ,

    If you want to limit users in your SharePoint Online site can view and edit without uploading or downloading documents, please refer to the following steps:

    1.Create a custom permission level:
    Go to Settings -> Site permissions -> Advanced permission settings -> Permission Levels in Ribbon -> Add a Permission Level:

    2.Select the base permissions you want to include in this permission level.
    36028-2-1.png
    36007-2-2.png

    Please remember to uncheck “Open items”, per my test, this permission decides whether users can download documents in your site.

    If I grant users with a permission level including “Open items”, the users can download documents:
    35973-2-3.png

    If I grant users with a permission level excluding “Open items”, the users cannot download documents:
    36051-2-4.png

    3.Create a group in Advanced permission settings:
    Give the permission level you created above to this group:
    36042-2-5.png
    4.Add guest users to this group. Then the guest users can view and edit documents but can’t upload or download a document under this permission level.

    I hope this information has been useful, please let me know if you still need assistance.


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  2. Leo Visser 91 Reputation points MVP
    2020-10-29T00:06:23.877+00:00

    The conditional access allows the devices to access the web app. But the settings to check what guest users can actually do you have to set in Sharepoint itself.
    See:
    https://learn.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices#limit-access

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.