Hmmm, afaik it does: see here: and section restrict access to content. AFAIK, the other user it has been shared with cannot access it.

In terms of downloading, well, you would probably look to use app protection policies using Intune in order to block downloads on non managed devices

Or you could look to apply sensitivity labels, for example on Teams to require the device to be managed

If you were taking a zero trust policy no device accessing the corporate access or applications would be non-managed.

