logo
search
Data Protection Issues

Block Microsoft 365 Web App Downloads with Defender or Purview

Maira MehtabMaira Mehtab Sep 25, 2026 869 views

Question details

Administrators need a way to prevent users from downloading copies of files from Microsoft 365 web applications on unmanaged devices.

How to Block Microsoft 365 Web App Downloads on Unmanaged Devices
Product
Microsoft 365 Web Apps
Device & OS
not provided
Scenario
Securing company data by applying strict download restrictions to web-based Office applications when accessed from devices not managed by the organization.
Observed behavior
Organizations need different data protection controls for Word and Excel web apps compared to Outlook to successfully block the 'Download as Copy' feature.
Before you start

Ensure you have global administrator or security administrator privileges in your Microsoft 365 tenant, and verify that your organization is licensed for Microsoft Defender for Cloud Apps or Microsoft Purview.

Solution 1Recommended

Use Microsoft Defender for Cloud Apps Session Policies

Configure session policies in Defender for Cloud Apps to monitor and restrict file downloads in real-time based on the device's management status.

Microsoft Defender for Cloud Apps provides granular control over user sessions. By leveraging Conditional Access App Control, you can enforce policies that specifically block downloads from Word, Excel, and other Microsoft 365 web apps when accessed from unmanaged devices.

1
Access the Defender Portal

Log in to the Microsoft Defender portal as an administrator and navigate to 'Cloud Apps' > 'Policies' > 'Policy management'.

2
Create a Session Policy

Click 'Create policy' and select 'Session policy'. Choose 'Control file download (with inspection)' from the policy template dropdown.

3
Configure Device Filters

In the 'Activity source' section, add a filter for 'Device Tag' and set it to 'does not equal' 'Intune compliant' or 'Hybrid Azure AD joined' to target unmanaged devices.

4
Set the Action to Block

Under the 'Actions' section, select 'Block' and customize the block message that users will see when they attempt to download a file. Save and enable the policy.

Use Microsoft Defender for Cloud Apps Session Policies
Policy Propagation: It may take up to 24 hours for new session policies to fully propagate and take effect across all Microsoft 365 web applications.
Free Microsoft Office alternative

Secure Your Documents Locally with WPS Office

Managing complex cloud policies in Microsoft 365 can be overwhelming. WPS Office provides a highly secure, lightweight, and offline-capable alternative with built-in document encryption, ensuring your data stays protected without requiring complicated tenant configurations.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install WPS Office: Run the installer and follow the on-screen instructions to set up the suite on your device.
  3. 3. Apply Document Passwords: Open any document, go to 'Menu' > 'Document Encryption', and set a password to securely restrict editing or extracting data.
Free, lightweight, and easy to deploy across your entire organizationStrict local document encryption and permission controlsSeamless compatibility with Microsoft Word, Excel, and PowerPoint formatsFamiliar user interface ensuring zero learning curve for teams
QA img-9

Frequently Asked Questions

Why do Word and Excel web apps require different controls than Outlook on the web?

Outlook on the web relies on Exchange Online policies, such as Outlook Web App (OWA) mailbox policies, to restrict attachment downloads. Word and Excel web apps, however, interface directly with SharePoint Online and OneDrive, requiring Defender for Cloud Apps or Purview for granular, file-level download restrictions.

Can users still view documents online if 'Download as Copy' is blocked?

Yes. When configured correctly using Defender for Cloud Apps session policies, users on unmanaged devices can still open, view, and edit documents directly within the browser without having the ability to download a local copy.

Can I apply these download restrictions to specific user groups only?

Absolutely. Both Microsoft Defender for Cloud Apps and Microsoft Purview allow you to scope your policies to specific Azure AD users or groups, ensuring that restrictions only apply to intended departments or external contractors.

Will blocking downloads affect users on managed company devices?

No, provided you configure the device filters correctly. By setting the policy to target only devices that are not 'Intune compliant' or 'Hybrid Azure AD joined', users on managed company devices will retain full download capabilities.