OneDrive can now silently excluded files from sync
Office 365 (OneDrive) Monday, 07 December 2020 by paul

With OneDrive Admin Center you could block files from being synced but this would display an error on the users OneDrive client. The latest production client of OneDrive includes a new feature allowing file names or extensions to be excluded from the sync without any error showing to the user. This can be done with the following steps.

  1. Download and install the latest OneDrive client (20.210.1005.0009) from Microsoft: https://support.microsoft.com/en-us/office/onedrive-release-notes-845dcf18-f921-435e-bf28-4e24b95e5fc0?ui=en-us&rs=en-us&ad=us
  2. Copy the policy files from "C:\Program Files (x86)\Microsoft OneDrive\20.201.1005.0009\adm" to the domain controller "\\domain\sysvol\domain\Policies\PolicyDefinitions"
  3. Edit the required group policy setting "Computer Configuration -> Policies -> Administrative Templates -> OneDrive -> Excluded Specific kinds of files from being uploaded". For example add ".exe" to block executable files.

This will only apply to new uploads and the existing files remain in the users local OneDrive folders. The only indication to the user in explorer is a different symbol next to the file show their sync status as "Excluded from sync".

