logo
search
Data Protection Issues

How to Block All File Uploads to SharePoint and OneDrive

Maira MehtabMaira Mehtab Sep 25, 2026 869 views

Question details

Organizations need a way to universally prevent users from uploading files to SharePoint and OneDrive via browsers, sync clients, Teams, and other Microsoft 365 apps.

How to Block All File Uploads to SharePoint and OneDrive
Product
Microsoft 365
Device & OS
not provided
Scenario
Enforcing organizational data protection policies to restrict unauthorized data storage or exfiltration to the cloud.
Observed behavior
Blocking the OneDrive sync client alone leaves loopholes, as users can still upload documents using web browsers or other Microsoft applications.
Before you start

Ensure you have administrative privileges to the Microsoft 365 Admin Center, Microsoft Purview, and Microsoft Defender to configure organization-wide security policies.

Solution 1Recommended

Implement Session Policies and Endpoint DLP

Use Microsoft Purview and Defender for Cloud Apps to monitor and block file uploads across both web browsers and desktop applications.

Because there is no single master switch to disable all Microsoft 365 uploads, organizations must combine Endpoint Data Loss Prevention (DLP) and Microsoft Defender session policies. This combination ensures proper coverage across web browsers, the OneDrive sync client, and Microsoft Teams.

1
Access Microsoft Purview

Log in to the Microsoft Purview compliance portal using an account with Global Administrator or Compliance Administrator permissions.

2
Configure Endpoint DLP

Navigate to the Data Loss Prevention section and create a new policy targeting endpoint devices. Configure the rules to monitor and restrict file copying or uploading to unauthorized cloud storage domains.

3
Set up Defender for Cloud Apps

Open the Microsoft Defender portal and create a new Session Policy. Set the policy to 'Control file upload (with inspection)' to actively block file transfers to SharePoint Online and OneDrive via web browser sessions.

Implement Session Policies and Endpoint DLP
Coverage Dependencies: The effectiveness of these policies depends heavily on accurate configuration and user context. Thorough testing across all platforms (web, desktop, Teams) is required to ensure no upload paths are missed.
Free Microsoft Office alternative

Secure Your Local Workflows with WPS Office

If managing complex Microsoft 365 cloud policies and synchronization rules is too resource-intensive, consider switching to an offline-first solution. WPS Office provides comprehensive local document management, familiar interfaces, and robust compatibility without forcing cloud uploads.

  1. 1. Download and Install: Get the official WPS Office installer from the website and follow the standard installation process on your devices.
  2. 2. Work Offline Securely: Create, edit, and review your documents locally without needing to sign into any mandatory cloud synchronization services.
  3. 3. Save Locally: Utilize default local save paths to ensure sensitive organizational data remains securely on your local drives.
Fully compatible with Microsoft Word, Excel, and PowerPoint file formats.Complete local file management to prevent unintended cloud data leaks.Lightweight software footprint with a highly familiar user interface.Enterprise-grade offline productivity without requiring complex DLP administration.
QA img-9

Frequently Asked Questions

Does stopping the OneDrive sync app prevent users from uploading files?

No. Pausing or disabling the OneDrive sync client only stops automatic background folder synchronization. Users can still manually upload files using their web browsers or Microsoft Teams.

Is there a single setting to block all Microsoft 365 uploads?

Currently, Microsoft 365 does not offer a universal toggle switch to block every upload path. Administrators must deploy a combination of Microsoft Defender for Cloud Apps and Purview Endpoint DLP policies to cover all applications.

Does a Cloud App session policy apply to desktop client apps?

Session policies in Defender for Cloud Apps primarily control activities within web browser sessions. To block file upload actions originating from native desktop applications, you must configure Endpoint DLP policies.