<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[gOxiA=苏繁=SuFan Blog]]></title> 
<link>https://maytide.net/index.php</link> 
<description><![CDATA[gOxiA,苏繁,sufan,Microsoft MVP]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[gOxiA=苏繁=SuFan Blog]]></copyright>
<item>
<link>https://maytide.net/read.php/1982.htm</link>
<title><![CDATA[通过 Intune 配置文件的管理模板限制邮件拷贝到本地 PST]]></title> 
<author>gOxiA &lt;sufan_cn@msn.com&gt;</author>
<category><![CDATA[Microsoft Cloud]]></category>
<pubDate>Thu, 26 Mar 2020 08:29:26 +0000</pubDate> 
<guid>https://maytide.net/read.php/1982.htm</guid> 
<description>
<![CDATA[ 
	<p><img alt="intune" src="http://goxia.maytide.net/ftpup/2018/fecf14ed538b_B2B9/intune_thumb.png"></p>&nbsp;&nbsp;<p><font color="#fd3f0d" size="4"><strong>通过 Intune 配置文件的管理模板限制邮件拷贝到本地 PST</strong></font></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 如果您是组织的 IT 管理员，正在使用 Office 365 和 Intune，且希望通过推送策略来限制用户客户端（Outlook）将邮件复制到本地的 PST 文件，那么现在可以通过 Intune “配置文件”下的“管理模板”来实现这一需求。</p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Intune 配置文件中的管理模板实现了之前 Windows GPO 的功能，除了可以配置 Windows 的计算机和用户配置，还可以使用已集成的应用策略对特定程序进行配置，例如：Microsoft Edge，Office 的 Word、Excel、Outlook 等程序。在过去 GPO 管理环境下，则需要先导入 Office ADMX 或 Edge ADMX。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/AdminTemplates_3.png"><img width="499" height="379" title="AdminTemplates" style="border: 0px currentcolor; border-image: none; display: inline; background-image: none;" alt="AdminTemplates" src="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/AdminTemplates_thumb_3.png" border="0"></a></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 今天 <a href="http://goxia.maytide.net" target="_blank">gOxiA</a> 将演示如何配置管理模板来阻止用户在 Outlook 下将邮件复制或移动到本地 PST 文件。当用户复制邮件到本地 PST 时，粘贴（Ctrl + V）操作会失效；如果移动邮件到 PST 会提示错误，效果如下图。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/blocktopst_3.png"><img width="504" height="379" title="blocktopst" style="border: 0px currentcolor; border-image: none; display: inline; background-image: none;" alt="blocktopst" src="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/blocktopst_thumb_3.png" border="0"></a></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 具体的操作如下：</p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 进入 <a href="https://devicemanagement.microsoft.com" target="_blank">Microsoft Endpoint Manager admin center</a> (<a href="https://devicemanagement.microsoft.com" target="_blank">Microsoft 365 设备管理</a>)，转到“<strong>设备</strong>” - “<strong>配置文件</strong>”，然后创建配置，“<strong>平台</strong>”选择 “<strong>Windows 10 and later</strong>”，“<strong>配置文件</strong>”选择“<strong>Administrative Templates</strong>”。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/1_3.png"><img width="634" height="379" title="1" style="border: 0px currentcolor; border-image: none; display: inline; background-image: none;" alt="1" src="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/1_thumb_3.png" border="0"></a></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 然后为配置文件起个易于识别的名称，如下图。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/2_3.png"><img width="634" height="296" title="2" style="border: 0px currentcolor; border-image: none; display: inline; background-image: none;" alt="2" src="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/2_thumb_3.png" border="0"></a></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 在配置设置下切换到“<strong>User Configuration</strong>”，展开至“<strong>Microsoft Outlook 2016 / 杂项 / PST 设置</strong>”，然后选中“<strong>禁止用户将新内容添加到现有 PST 文件</strong>”，将其配置为“<strong>已启用</strong>”。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/3_3.png"><img width="634" height="379" title="3" style="border: 0px currentcolor; border-image: none; display: inline; background-image: none;" alt="3" src="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/3_thumb_3.png" border="0"></a></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 之后将配置文件分配给特定的组，或所有用户。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/4_3.png"><img width="634" height="357" title="4" style="border: 0px currentcolor; border-image: none; display: inline; background-image: none;" alt="4" src="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/4_thumb_3.png" border="0"></a></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 最后审阅配置，并执行创建。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/5_3.png"><img width="634" height="722" title="5" style="border: 0px currentcolor; border-image: none; display: inline; background-image: none;" alt="5" src="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/5_thumb_3.png" border="0"></a></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 当应用到客户端上后，便会向客户端系统注册表写入相关键值，“<strong>HKCU\SOFTWARE\Policies\Microsoft\office\xx.0\outlook\pst</strong>”，增加名为“<strong>PSTDisableGrow</strong>”的键，“<strong>REG_DWORD</strong>”类型，值为“<strong>1</strong>”。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/policies_reg_3.png"><img width="634" height="434" title="policies_reg" style="display: inline; background-image: none;" alt="policies_reg" src="http://goxia.maytide.net/ftpup/2018/9844af619786_B086/policies_reg_thumb_3.png" border="0"></a></p>&nbsp;&nbsp;<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 如果是 OCT 进行配置的，则该键值位于“<strong>HKCU\Software\Microsoft\Office\xx.0\Outlook\PST</strong>”。IT 管理员需要注意的是由于该键值位于“HKCU”下，会有潜在的安全影响。</p>&nbsp;&nbsp;&nbsp;&nbsp;<p>参考文档：<a href="https://docs.microsoft.com/en-us/exchange/troubleshoot/outlook-policy/control-pst-use">https://docs.microsoft.com/en-us/exchange/troubleshoot/outlook-policy/control-pst-use</a></p>
]]>
</description>
</item>
</channel>
</rss>