How to Restrict Microsoft 365 Documents to Web-Only Access
Question details
The user wants to configure Microsoft 365 documents for web-only access to prevent recipients from downloading, copying, printing, or capturing the information.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Sharing sensitive documents externally or internally where recipients should only view the file in a browser without being able to save or extract the data.
- Observed behavior
- Standard view-only sharing links do not completely prevent data capture, as users may still print, take screenshots, or download depending on the specific link settings and account policies.
Verify that your Microsoft 365 subscription includes advanced compliance features, as strict Data Loss Prevention (DLP) and Microsoft Purview policies require specific premium enterprise licenses.
Use Block Download in OneDrive and SharePoint
The most straightforward way to restrict access to web-only viewing is by utilizing the built-in 'Block download' toggle when generating a sharing link.
This feature allows recipients to view the document entirely within the browser while disabling the download button and preventing them from copying text or opening the file in desktop applications.
Navigate to the file in OneDrive or SharePoint online, right-click the document, and select 'Share'.
Click the gear icon or the link configuration text (e.g., 'Anyone with the link can edit') to open the sharing settings menu.
Under 'More settings', ensure that the 'Allow editing' checkbox is unchecked to enforce view-only access.
Toggle the 'Block download' switch to the ON position. Click 'Apply' and copy the generated link to share with your recipients.

Apply Microsoft Purview Information Protection Labels
For highly sensitive enterprise data, administrators can enforce strict access controls using Information Rights Management (IRM) and sensitivity labels.
Protect and Share Documents Securely with WPS Office
If managing complex Microsoft 365 compliance policies is overwhelming or requires expensive enterprise licenses, consider WPS Office. It serves as a free, lightweight, and easy-to-use alternative with a familiar UI, seamless format migration, and built-in secure cloud sharing capabilities.
- 1. Open Your File: Launch WPS Office and open the document you wish to share securely.
- 2. Create a Secure Link: Click the 'Share' button in the top right corner and select 'Create Link'.
- 3. Set Permissions: Change the permission level to 'View Only' and configure the link to expire after a certain date or require a password for added web security.

Frequently Asked Questions
Can I completely prevent someone from taking a screenshot of my shared document?
No browser-based web-only control can completely prevent a user from taking screenshots or capturing the screen with external software. While some enterprise DRM solutions add friction or apply dynamic watermarks, absolute prevention on an unmanaged device is currently impossible.
Why is the 'Block download' option grayed out in SharePoint and OneDrive?
The 'Block download' option is only available when the document sharing link is set to 'View only' (meaning 'Allow editing' is unchecked). Additionally, your organization's global Microsoft 365 sharing policies may have restricted this feature, requiring admin intervention.
Does web-only access in Microsoft 365 restrict printing?
Standard view-only access via sharing links may still allow users to print the browser page using their browser's native print function. To strictly block printing, you must apply Information Rights Management (IRM) policies or sensitivity labels using Microsoft Purview.




