Manger wants total control over employee data

milo last 85 Reputation points
2024-03-23T10:17:23.48+00:00

A Manager wants to have total control over 5 employee data.

The laptop is provided by the Company and any file created by the employee, the Manager should be able to see it. No files should be deleted by the employee even if the employee is the owner of the document it. Is there any solution from Microsoft using Intune , Conditional access or DLP ?

Microsoft Security | Intune | Security
Microsoft Security | Intune | Configuration
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Purview
{count} votes

2 answers

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 13,341 Reputation points MVP
    2024-03-23T11:51:13.31+00:00

    DLP. Not sure is this possible to have such control in user profile's OneDrive folders.

    0 comments No comments

  2. Cathryn Symons 0 Reputation points
    2024-03-24T13:15:42.7333333+00:00

    I'm not sure that intune or conditional access are the tools for this. I would use Purview (ie DLP or Data Loss Prevention)
    If you set a retention hold, files are retained for the retention period which can be indefinite. https://learn.microsoft.com/en-us/purview/create-retention-policies?tabs=other-retention

    And give the manager access to all onedrives, tell staff not to delete files, and also give the manager access to the retention hold folders.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.