Directory-based encryption and OneDrive/SharePoint functionality

Stanislav Malkin 1 Reputation point
2022-04-01T13:34:22.33+00:00

Hi,

our customers use our product to transparently encrypt files in specific directories. Some customers encrypt files in a OneDrive synced directory.
Since OneDrive.exe does not have access to plaintext data, it works fine most of the time and encrypted files are uploaded into the cloud in encrypted form.

Unfortunately, we have found out that Office Products like Word/Excel & Co. sometimes access the cloud directly (even if the Office Sync and Connected Experiences are deactivated) and therefore sometimes plain text data ends up in the cloud, which, of course, should not happen. If we block Word/Excel communication with a firewall, Word works more or less well (although very slowly), but Excel, for example, cannot save any files at all anymore.

What would be the best way to combine directory-based encryption with OneDrive/SharePoint/Cloud funcktionality?
Are there settings or is it somehow possible to ban all network communication of the Office Products without losing basic functionality?

Microsoft 365 and Office Install, redeem, activate For business Windows
Microsoft 365 and Office SharePoint For business Windows
Microsoft 365 and Office OneDrive For business Windows
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Emily Hua-MSFT 27,796 Reputation points
    2022-04-04T09:08:49.83+00:00

    Hi @Stanislav Malkin

    Welcome to Q&A forum ~

    > What would be the best way to combine directory-based encryption with OneDrive/SharePoint/Cloud funcktionality?

    Currently OneDrive's own encryption is used to protect shared files.
    I want to give you some suggestions, but I do not find any Microsoft official documentations to to describe this issue. Thanks for your understanding.
    To help you better, it's best to open a support ticket with Microsoft Support to help review your problem and help you test remotely.

    > Are there settings or is it somehow possible to ban all network communication of the Office Products without losing basic functionality?

    Could you please tell us which actions does "Office Sync and Connected Experiences are deactivated" point to?

    From an Office perspective, please refer to "(This feature has been disabled by your administrator) error in Microsoft Office", and try to configure the specified registry values under Cause section.
    UseOnlineContent --- Value: 0
    SignInOptions --- Value: 3
    But please note, if you are running Microsoft 365 apps, I do not suggest you set values for SignInOptions to be 1 or 3.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.



Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.