Setting up and managing device configurations using Intune
Disabling file saving to local storage and redirecting Downloads to SharePoint/OneDrive are two different controls and are configured in different places. From the provided information, only the app-protection side of blocking local storage is covered.
1. Disable saving corporate data to local storage (Intune App Protection Policies)
For mobile/APP-managed scenarios (for example, Outlook, Office apps on iOS/Android), saving corporate files to local storage is controlled by Intune App Protection Policies (APP):
If users cannot save corporate files to local storage, it is typically because:
- Send org data to other apps is set to None.
- Allow user to save copies to selected services is not set to local storage.
To block saving to local storage for corporate data:
- In Intune, edit the relevant App protection policy.
- Set Send org data to other apps to a restrictive value (for example, None or a policy-managed option) so data cannot be sent to unmanaged/local apps.
- Ensure Allow user to save copies to selected services does not include local storage.
This combination prevents saving corporate files to local storage from APP-managed apps.
Note: Some behaviors are app-specific. For example, for Outlook for iOS, the setting Select which storage services corporate data can be saved to does not apply to images in email messages; images can still be saved locally by design.
2. Redirecting Downloads to SharePoint/OneDrive using Intune
The provided material does not include a supported method to:
- Redirect the Windows Downloads folder to SharePoint/OneDrive using Intune, or
- Enforce that all browser/OS downloads land in a SharePoint/OneDrive-backed location.
The context only covers:
- Redirecting macOS Desktop and Documents folders to OneDrive via the OneDrive sync client and configuration tools like Intune, Jamf, etc.
- Managing Windows App (Azure Virtual Desktop/Windows 365) device, audio, clipboard, and folder redirection for remote sessions.
These do not provide a policy to redirect the local Downloads folder to SharePoint/OneDrive via Intune.
To protect data in SharePoint/OneDrive, the context instead shows how to block downloading from specific SharePoint sites or OneDrive using Set-SPOSite -BlockDownloadPolicy $true, which prevents local copies from being created from those locations, but does not redirect Downloads.
References:
- Common data transfer issues and scenarios
- App protection policy doesn't restrict saving images locally in Outlook for iOS
- Redirect and move macOS Desktop and Documents folders to OneDrive
- Block download policy for SharePoint sites and OneDrive
- Redirect local devices, audio, and folders in Windows App
- Manage Windows App redirection settings with Microsoft Intune