How to Prevent Users From Making Network Files Available Offline Using Microsoft Intune
This policy stops users from manually syncing network files and folders to their device for offline access. It removes the “Make Available Offline” (also called “Always Available Offline”) option from the right-click context menu. Automatic caching of admin-designated shares still works — only manual user action is blocked.
Why Use It
It helps prevent sensitive corporate data from being stored on unmanaged or shared devices. Good fit for orgs that want tighter control over what ends up cached locally on endpoints.
How to Set It Up
- Sign in to the Intune Admin Center
- Go to Devices > Configuration > + Create > New Policy
- Set Platform to Windows, give it a name (e.g. Remove “Make Available Offline” command)
- In Configuration Settings, click + Add Settings
- In the Settings Picker, search for “Make Available Offline” or navigate to: Administrative Templates > Network > Offline Files
- Select Remove “Make Available Offline” command
- Toggle the setting to Enabled (turns blue)
- Assign to a test device group first, then expand rollout
Verify It Worked
After deployment, go to Devices > Configuration Profiles, select the policy, and check Device Status — you want to see Succeeded.
You can also confirm via Event Viewer: navigate to Applications and Services Logs > Microsoft > Windows > Device Management > Enterprise Diagnostic Provider > Admin and filter for Event ID 819.
