Post

Control Add Shortcut to OneDrive with a tenant-level setting

Diesen Beitrag auf Deutsch lesen

A focused PnP PowerShell script disables SharePoint Online Add Shortcut to OneDrive across the tenant using certificate-based authentication.

TL;DR

Set DisableAddToOneDrive = True to disable SharePoint Online Add Shortcut to OneDrive at tenant level. The described PnP PowerShell workflow connects to the SharePoint Online administration site with an Azure AD app registration and certificate, logs execution, reports success or failure, and disconnects cleanly.

Original by Josiah Opiyo, on Microsoft 365 and Power Platform Community Blog. Read the original

This is our own summary, not a republication or full translation.

Governance takeaway

  • Admins/CoE: Apply DisableAddToOneDrive at tenant level with a focused PnP PowerShell script when site-by-site or manual administration is unsuitable.
  • Security/Compliance: Use the described non-interactive app registration and certificate authentication, while retaining configuration and execution logging for a repeatable administrative process.
  • Leadership/Business: Decide whether the convenience of SharePoint shortcuts outweighs governance and support concerns, since the setting removes the feature across the tenant.
This post is licensed under CC BY 4.0 by the author.