How to make Microsoft Team only allowed download files on whitelist device ?
So, is there possible to enforce, or at least detect if files uploaded on Microsoft Team, outlook (enterprise) is only downloadable on company provided device ?
Why are you asking this here? This is meant more for asking about thoughts and experiences rather than tech support. You’d probably have better luck in a more technical community (or just googling it). You may still get some answers though 🤷
Are you the admin on your Teams team? Do you have access to the Advanced Directory/Azure Domain controls?
If not, you're going to have to have an admin do any kind of set up of that type.
The first major issue is that looks like most download controls in Teams are on a per-user basis, meaning that the easiest way to block downloads is to deny the user access from downloading entirely.
It seems like there are options for Android management that allow you to block an Android device from downloads as well.
But I can't seem to find anything on blocking specific other devices from downloads, and all the stuff I'm digging up circles back around to blocking the user from downloading entirely, instead of blocking them on a per-device level.
This one shows that they have admin options like this:
"5. Under "Actions", select "Block access" and choose the conditions you want to apply (e.g. "Block access when user is outside of company network")."
So perhaps in the admin settings there's more fine-grained options like this? I still don't see references to blocking per-device, just stuff like being outside the enterprise network.
Why not just block access to Teams and other m365 apps via conditional access from non-managed devices then?
You can always "download" any content you're viewing on the device, in fact you need to do so in order to view it.
Say, you don't want a word document containing price sensitive information being downloaded, but someone with access to view the document on a non-managed device can just screenshot it. Or to be honest, just take a photo from a screen of a managed device.