How to Block All File Uploads to SharePoint and OneDrive
Question details
Organizations need a way to universally prevent users from uploading files to SharePoint and OneDrive via browsers, sync clients, Teams, and other Microsoft 365 apps.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Enforcing organizational data protection policies to restrict unauthorized data storage or exfiltration to the cloud.
- Observed behavior
- Blocking the OneDrive sync client alone leaves loopholes, as users can still upload documents using web browsers or other Microsoft applications.
Ensure you have administrative privileges to the Microsoft 365 Admin Center, Microsoft Purview, and Microsoft Defender to configure organization-wide security policies.
Implement Session Policies and Endpoint DLP
Use Microsoft Purview and Defender for Cloud Apps to monitor and block file uploads across both web browsers and desktop applications.
Because there is no single master switch to disable all Microsoft 365 uploads, organizations must combine Endpoint Data Loss Prevention (DLP) and Microsoft Defender session policies. This combination ensures proper coverage across web browsers, the OneDrive sync client, and Microsoft Teams.
Log in to the Microsoft Purview compliance portal using an account with Global Administrator or Compliance Administrator permissions.
Navigate to the Data Loss Prevention section and create a new policy targeting endpoint devices. Configure the rules to monitor and restrict file copying or uploading to unauthorized cloud storage domains.
Open the Microsoft Defender portal and create a new Session Policy. Set the policy to 'Control file upload (with inspection)' to actively block file transfers to SharePoint Online and OneDrive via web browser sessions.

Open a Microsoft 365 Support Request
For complex enterprise environments, work directly with Microsoft support engineers to design a comprehensive restriction policy.
Secure Your Local Workflows with WPS Office
If managing complex Microsoft 365 cloud policies and synchronization rules is too resource-intensive, consider switching to an offline-first solution. WPS Office provides comprehensive local document management, familiar interfaces, and robust compatibility without forcing cloud uploads.
- 1. Download and Install: Get the official WPS Office installer from the website and follow the standard installation process on your devices.
- 2. Work Offline Securely: Create, edit, and review your documents locally without needing to sign into any mandatory cloud synchronization services.
- 3. Save Locally: Utilize default local save paths to ensure sensitive organizational data remains securely on your local drives.

Frequently Asked Questions
Does stopping the OneDrive sync app prevent users from uploading files?
No. Pausing or disabling the OneDrive sync client only stops automatic background folder synchronization. Users can still manually upload files using their web browsers or Microsoft Teams.
Is there a single setting to block all Microsoft 365 uploads?
Currently, Microsoft 365 does not offer a universal toggle switch to block every upload path. Administrators must deploy a combination of Microsoft Defender for Cloud Apps and Purview Endpoint DLP policies to cover all applications.
Does a Cloud App session policy apply to desktop client apps?
Session policies in Defender for Cloud Apps primarily control activities within web browser sessions. To block file upload actions originating from native desktop applications, you must configure Endpoint DLP policies.




