How OneDrive safeguards your data in the cloud (2024)

You control your data. When you put your data in OneDrivecloud storage, you remain the owner of the data. For more info about the ownership of your data, see Office 365 Privacy by Design.

See this training course to learnabout OneDrive features that you can use to protect your files, photos and data:Secure, protect and restore OneDrive

How you can safeguard your data

Here are some things you can do to help protect your files in OneDrive:

  • Create a strong password. Check the strength of your password.

  • Add security info to your Microsoft account. You can add info like your phone number, an alternate email address, and a security question and answer. That way, if you ever forget your password or your account gets hacked, we can use your security info to verify your identity and help you get back into your account. Go to the Security info page.

  • Use two-factor verification. This helps protect your account by requiring you to enter an extra security code whenever you sign in on a device that isn’t trusted. The second factor can be made through a phone call, text message, or app. For more info about two-step verification, see How to use two-step verification with your Microsoft account.

  • Enable encryption on your mobile devices. If you have the OneDrive mobile app, we recommend that you enable encryption on your iOS or Android devices. This helps to keep your OneDrive files protected if your mobile device is lost, stolen, or someone gains access to it.

  • Subscribe to Microsoft 365. An Microsoft 365 subscription gives you advanced protection from viruses and cybercrime, and ways to recover your files from malicious attacks.

How OneDrive protects your data

Microsoft engineers administer OneDrive using a Windows PowerShell console that requires two-factor authentication. We perform day-to-day tasks by running workflows so we can rapidly respond to new situations. No engineer has standing access to the service. When engineers need access, they must request it. Eligibility is checked, and if engineer access is approved, it's only for a limited time.

Additionally, OneDrive and Office 365, strongly invests in systems, processes, and personnel to reduce the likelihood of personal data breach and to quickly detect and mitigate consequence of breach if it does occur. Some of our investments in this space include:

Access control systems: OneDrive and Office 365 maintain a “zero-standing access” policy, which means that engineers do not have access to the service unless it is explicitly granted in response to a specific incident that requires elevation of access. Whenever access is granted it is done under the principle of least privilege: permission granted for a specific request only allows for a minimal set of actions required to service that request. To do this, OneDrive and Office 365 maintain strict separation between “elevation roles,” with each role only allowing certain pre-defined actions to be taken. The “Access to Customer Data” role is distinct from other roles that are more commonly used to administer the service and is scrutinized most heavily before approval. Taken together, these investments in access control greatly reduce the likelihood that an engineer in OneDrive or Office 365 inappropriately accesses customer data.

Security monitoring systems and automation: OneDrive and Office 365 maintain robust, real-time security monitoring systems. Among other issues, these systems raise alerts for attempts to illicitly access customer data, or for attempts to illicitly transfer data out of our service. Related to the points about access control mentioned above, our security monitoring systems maintain detailed records of elevation requests that are made, and the actions taken for a given elevation request. OneDrive and Office 365 also maintain automatic resolution investments that automatically act to mitigate threats in response to issues we detect, and dedicated teams for responding to alerts that cannot be resolved automatically. To validate our security monitoring systems, OneDrive and Office 365 regularly conduct red-team exercises in which an internal penetration testing team simulates attacker behavior against the live environment. These exercises lead to regular improvements to our security monitoring and response capabilities.

Personnel and processes: In addition to the automation described above, OneDrive and Office 365 maintain processes and teams responsible for both educating the broader organization about privacy and incident management processes, and for executing those processes during a breach. For example, a detailed privacy breach Standard Operating Procedure (SOP) is maintained and shared with teams throughout the organization. This SOP describes in detail the roles and responsibilities both of individual teams within OneDrive and Office 365 and centralized security incident response teams. These span both what teams need to do to improve their own security posture (conduct security reviews, integrate with central security monitoring systems, and other best practices), and what teams would need to do in the event of an actual breach (rapid escalation to incident response, maintain and provide specific data sources that will be used to expedite the response process). Teams are also regularly trained on data classification, and correct handling and storage procedures for personal data.

The major takeaway is that OneDrive and Office 365, for both consumer and business plans, strongly invest in reducing the likelihood and consequences of personal data breach impacting our customers. If a personal data breach does occur, we are committed to rapidly notifying our customers once that breach is confirmed.

Protected in transit and at rest

Protected in transit

When data transits into the service from clients, and between datacenters, it's protected using transport layer security (TLS) encryption. We only permit secure access. We won't allow authenticated connections over HTTP, but instead redirect to HTTPS.

Protected at rest

Physical protection: Only a limited number of essential personnel can gain access to datacenters. Their identities are verified with multiple factors of authentication including smart cards and biometrics. There are on-premises security officers, motion sensors, and video surveillance. Intrusion detection alerts monitor anomalous activity.

Network protection: The networks and identities are isolated from the Microsoft corporate network. Firewalls limit traffic into the environment from unauthorized locations.

Application security: Engineers who build features follow the security development lifecycle. Automated and manual analyses help identify possible vulnerabilities. The Microsoft Security Response Center helps triage incoming vulnerability reports and evaluate mitigations. Through the Microsoft Cloud Bug Bounty Terms, people across the world can earn money by reporting vulnerabilities.

Content protection: Each file is encrypted at rest with a unique AES256 key. These unique keys are encrypted with a set of master keys that are stored in Azure Key Vault.

Highly available, always recoverable

Our datacenters are geo-distributed within the region and fault tolerant. Data is mirrored into at least two different Azure regions, which are at least several hundred miles away from each other, allowing us to mitigate the impact of a natural disaster or loss within a region.

Continuously validated

We constantly monitor our datacenters to keep them healthy and secure. This starts with inventory. An inventory agent performs a state capture of each machine.

After we have an inventory, we can monitor and remediate the health of machines. Continuous deployment ensures that each machine receives patches, updated anti-virus signatures, and a known good configuration saved. Deployment logic ensures we only patch or rotate out a certain percentage of machines at a time.

The Microsoft 365 "Red Team" within Microsoft is made up of intrusion specialists. They look for any opportunity to gain unauthorized access. The "Blue Team" is made up of defense engineers who focus on prevention, detection, and recovery. They build intrusion detection and response technologies. To keep up with the learnings of the security teams at Microsoft, see Security Office 365 (blog).

Additional OneDrive security features

As a cloud storage service, OneDrive has many other security features. Those include:

  • Virus scanning on download for known threats - The Windows Defender anti-malware engine scans documents at download time for content matching an AV signature (updated hourly).

  • Suspicious activity monitoring - To prevent unauthorized access to your account, OneDrive monitors for and blocks suspicious sign-in attempts. Additionally, we’ll send you an email notification if we detect unusual activity, such as an attempt to sign in from a new device or location.

  • Ransomware detection and recovery - As an Microsoft 365 subscriber, you will get alerted if OneDrive detects a ransomware or malicious attack. You’ll be able to easily recover your ​files to a point in time before they were affected, up to 30 days after the attack. You can also your restore your entire OneDrive up to 30 days after a malicious attack or other types of data loss, such as file corruption, or accidental deletes and edits.

  • Version history for all file types - In the case of unwanted edits or accidental deletes, you can restore deleted files from the OneDrive recycle bin or restore a previous version of a file in OneDrive.

  • Password protected & expiring sharing links - As an Microsoft 365 subscriber, you can keep your shared files more secure by requiring a password to access them or setting an expiration date on the sharing link.

  • Mass file deletion notification and recovery - If you accidentally or intentionally delete a large number of files in your OneDrivecloud backup, we will alert you and provide you with steps to recover those files.

Personal Vault

OneDrive Personal Vault is a protected area in OneDrive that you can only access with a strong authentication method or a second step of identity verification, such as your fingerprint, face, PIN, or a code sent to you via email or SMS.1 Your locked files in Personal Vault have an extra layer of security, keeping them more secured in case someone gains access to your account or your device. Personal Vault is available on your PC, on OneDrive.com, and on the OneDrive mobile app, and it also includes the following features:

  • Scan directly into Personal Vault - You can use the OneDrive mobile app to take pictures or shoot video directly into your Personal Vault, keeping them off less secure areas of your device—such as your camera roll.2 You can also scan important travel, identification, vehicle, home, and insurance documents directly into your Personal Vault. And you’ll have access to these photos and documents wherever you go, across your devices.

  • BitLocker-encryption - On Windows 10 PCs, OneDrive syncs your Personal Vault files to a BitLocker-encrypted area of your local hard drive.

  • Automatic locking - Personal Vault automatically relocks on your PC, device, or online after a short period of inactivity. Once locked, any files you were using will also lock and require re-authentication to access.3

Together, these measures help keep your locked Personal Vault files protected even if your Windows 10 PC or mobile device is lost, stolen, or someone gains access to it.

1 Face and fingerprint verification requires specialized hardware including a Windows Hello capable device, fingerprint reader, illuminated IR sensor, or other biometric sensors and capable devices.
2 The OneDrive app on Android and iOS requires either Android 6.0 or above or iOS 12.0and above.
3 Automatic locking interval varies by device and can be set by the user.

Need more help?

How OneDrive safeguards your data in the cloud (1)

Contact Support
For help with your Microsoft account andsubscriptions, visit.

For technical support, go to Contact Microsoft Support, enter your problem and select Get Help. If you still need help, selectContact Supportto be routed to the best support option.

How OneDrive safeguards your data in the cloud (2)

Admins
Admins should view Help for OneDrive Admins, the OneDrive Tech Community or contactMicrosoft 365 for business support.

How OneDrive safeguards your data in the cloud (2024)

FAQs

How OneDrive safeguards your data in the cloud? ›

Suspicious activity monitoring - To prevent unauthorized access to your account, OneDrive monitors for and blocks suspicious sign-in attempts. Additionally, we'll send you an email notification if we detect unusual activity, such as an attempt to sign in from a new device or location.

How does OneDrive protect files? ›

OneDrive encryption: OneDrive applies robust encryption technology to data at rest and in transit. Disk-level encryption is used at rest and each file is encrypted using a unique AES256 key. These keys are encrypted with a set of master keys stored in Azure Key Vault.

What is the security level of OneDrive? ›

Microsoft uses an AES 256 key for every file at rest within OneDrive. An AES (Advanced Encryption Standard) 256 key has 256 bits (a bit can be thought of as one character, or one single element) and goes through 14 rounds of security to secure it.

What is the purpose of cloud storage such as Microsoft OneDrive? ›

OneDrive is the Microsoft cloud service that connects you to all your files. It lets you store and protect your files, share them with others, and get to them from anywhere on all your devices.

How does Microsoft secure my data? ›

We secure your data at rest and in transit

With advanced encryption, Microsoft helps protect your data both at rest and in transit. Our encryption protocols erect barriers against unauthorized access to the data, including two or more independent encryption layers to safeguard against compromises of any one layer.

How does OneDrive work? ›

OneDrive allows you to create files on your computer and edit them on a tablet or smartphone while saving all of your changes. Windows Phone, Android, iOS, and Xbox are all supported. You can access the same file from any device without having to send it via email or save it to a memory stick.

Can OneDrive access your files? ›

OneDrive is an integral part of Office 365. OneDrive is a Microsoft-hosted location where employees can store and share files and access files from anywhere using any Internet-connected device.

Who can see my files on OneDrive? ›

Anyone who gets the link can view or edit the item, depending on the permission you set. Users with the link cannot upload new items. If the sharing link points to a folder, you may be required to sign in with a Microsoft account.

Which is more secure OneDrive or Google Drive? ›

Both Google Drive and OneDrive have encryption settings for data to better protect data security, and both have authentication for account security. But OneDrive is a little more careful in terms of security features.

What is the limit of OneDrive cloud? ›

For most subscription plans, the default storage space for each user's OneDrive is 1 TB. Depending on your plan and the number of licensed users, you can increase this storage up to 5 TB.

What is the benefit of OneDrive? ›

OneDrive is designed to provide users immediate access to their data no matter where they are, on any device. For instance, a user might start editing an MS Office document on their desktop at work, view it on their mobile device as they commute home, and seamlessly resume working on it from their MacBook that evening.

Does OneDrive lets you keep your file in the cloud? ›

OneDrive lets you store all your work files in one secure place in the cloud. You can get to your files from any device, wherever you are, and you can share and collaborate with others on any file. On OneDrive, your files are backed up and protected. And you control if and when other folks can see them.

What is a disadvantage of using OneDrive? ›

The disadvantages of OneDrive are limited sharing options, limited file management and desktop synchronise settings. Limited Sharing Options: OneDrive's sharing options are limited compared to other cloud storage services, making it difficult to share files with non-Microsoft users.

Where is OneDrive data stored? ›

Where does OneDrive store files? In the post above, now you know the OneDrive files are all stored in the C drive, and also, you've learned how to disable the synchronization between the OneDrive cloud and your personal computer.

Can Microsoft access my cloud data? ›

A majority of our service operations are automated so that only a small set requires human interaction. Microsoft engineers don't have default access to cloud customer data. Instead, they are granted access, under management oversight, only when necessary.

How do I encrypt files in OneDrive? ›

Right-click the folder or file that you want to encrypt, and then select Properties. Select the General tab, and then select Advanced. Select the Encrypt contents to secure data check box, click OK, and then click OK again.

What happens to OneDrive files? ›

When restoring, any files or folders created after the Restore point date will be sent to your OneDrive Recycle Bin. If a file has been permanently deleted from your OneDrive Recycle Bin, then it can never be recovered.

What is the difference between OneDrive and OneDrive? ›

Rebranding – Both SkyDrive and SkyDrive Pro had been rebranded. Nowadays, SkyDrive is known as OneDrive and SkyDrive Pro is known as OneDrive for Business. Cloud Storage Capacity – SkyDrive (OneDrive) is designed for personal use. You can use it to store files like images, documents, and more.

Why is OneDrive syncing everything? ›

Why OneDrive Syncing Everything? Sometimes, OneDrive syncs everything because you have enabled the Manage Backup feature. And you often save your files to Documents, Pictures, Desktop folders but you do not want to sync them to OneDrive. As a result, OneDrive will sync everything automatically.

Does OneDrive share your data? ›

With your files in OneDrive cloud storage, you can share them with others, control who can view or edit them, and work together at the same time.

Does OneDrive scan your photos? ›

Scan a whiteboard, document, business card, or photo in OneDrive for Android. You can scan whiteboards, business cards, documents, or photos with the OneDrive app and automatically save them to your OneDrive for later use. . You can also tap Add at the bottom of the screen, then tap Scan.

Can my company see my personal OneDrive files? ›

Who can see my files? OneDrive is personal to you; only you will be able to view and edit your files unless you decide to share them with others.

Can my boss access my OneDrive? ›

If the boss and the admins are not in the same tenant of yours, they will not have the permission to access your OneDrive for Business. But it's still not a good choice to save your personal files in OneDrive for Business.

How can I tell if someone has viewed my OneDrive? ›

OneDrive
  1. Find the file that you would like to check.
  2. Hover your cursor over the file name.
  3. When the information pop up opens, viewers of the file will be listed at the bottom.
Oct 13, 2021

Should I save all my files to OneDrive? ›

If you're working on a file by yourself, save it to OneDrive. Your OneDrive files are private unless you share them with others, which is particularly useful if you haven't created a team yet.

What is better than OneDrive? ›

Google Drive offers three times more space and more additional possibilities than Microsoft OneDrive. If your needs surpass any of these offerings, you can get an upgrade to one of the paid business plans and get unlimited cloud storage, cloud backup, file sync on all deskop and mobile devices, and more.

How much does OneDrive cost per year? ›

Home storage plans
Home storage plansDetailsPrice
OneDrive BasicOneDrive Only.Free
OneDrive StandaloneOneDrive Only.$1.99 / month
Microsoft 365 PersonalOffice apps.$69.99 / year
Microsoft 365 FamilyUp to 6 people.Office apps.$99.99 / year
Feb 23, 2021

Do I really need OneDrive? ›

No, OneDrive is not necessary for Windows. You can uninstall it if you do not want to use it, and use other tools, like EaseUS Todo Backup Home to protect your data.

What happens if OneDrive is full? ›

If you exceed your OneDrive storage quota: You won't be able to upload, edit, or sync new files (such as Camera Roll) to your OneDrive. Your existing files will remain but will be read-only.

How do I get 1TB OneDrive for free? ›

OneDrive for Business provides a variety of plans for different users, even the most basic plan provides OneDrive 1TB free cloud storage for each member of the organization. If you think there is a package that suits you, you can go to check the OneDrive for Business plan and subscribe.

How do I clean my OneDrive? ›

First, select Recycle bin in the OneDrive left side navigation.
  1. To permanently delete specific files or folders from the recycle bin, select those items, then select Delete in the top navigation.
  2. To permanently delete the entire recycle bin at once, select Empty recycle bin in the top navigation.

Does Microsoft OneDrive expire? ›

You will not be able to send or receive any Microsoft Teams messages which contain attachments. After 12 months, we may delete your OneDrive and all files within it.

Is OneDrive the same as cloud storage? ›

Microsoft OneDrive for Business is a sync / cloud storage service and works almost the same as DropBox or Google Drive. OneDrive is a service where you log in with a private or corporate account in the client and choose which folders to sync to the cloud.

How do I keep all my OneDrive files on the cloud? ›

Open OneDrive settings (select the OneDrive cloud icon in your notification area, and then select the OneDrive Help and Settings icon then Settings.) Go to the Sync and back up tab and expand the Advanced settings. Under Files On-Demand, select either Download files as you use them or Download all files now.

Is data stored in OneDrive backed up? ›

When your files finish syncing to OneDrive, they're backed up and you can access them from anywhere in Documents, or Desktop.

How do I keep files on my computer but not OneDrive? ›

Go to PC Settings, using the PC Settings tile in the Start menu, or swipe in from the right edge of the screen, select Settings, and then select Change PC settings. Under PC settings, select OneDrive. On the File Storage tab, turn off the switch at Save documents to OneDrive by default.

How do I save files to my computer instead of OneDrive? ›

Open any Office app, such as Word or Excel. Click the File menu in the top left corner. Select Options from the left pane. In the Save tab, tick the Save to Computer by default option.

Who can see my cloud data? ›

In cloud computing you move your data, applications and processes into third-party domains that you then access remotely. Whomever you entrust your data to will, therefore, be able to see it, and that's a fact you have to accept. Your hosting provider is responsible for the storage and safety of your data.

Do other people have access to my cloud? ›

How to add other users to your My Cloud? You can add additional users to your My Cloud device for local access, and you can also invite those users to give them cloud access to store and access the content from a remote location.

Can people access your cloud? ›

Once a hacker gains access to an account, they can use the cloud infrastructure to access other accounts. If they manage to access an account belonging to the cloud provider, then the attack would be much more extensive.

Is OneDrive fully encrypted? ›

Content protection: Each file is encrypted at rest with a unique AES256 key. These unique keys are encrypted with a set of master keys that are stored in Azure Key Vault.

Is OneDrive secure and private? ›

Best Industry-Standard Practices

Cloud services take secure your data in many ways. With OneDrive, you get additional security features that elevate your experience: Virus scanning for known threats thanks to the Windows Defender anti-malware engine. Suspicious activity monitoring to prevent unauthorized access.

What is the best encryption for OneDrive? ›

Overall, OneDrive can protect your data using many advanced security features. But if you want to encrypt your files on OneDrive, you will get a robust encryption option called Personal Vault. It is a secure place that can safeguard your important files with a strong security system.

What are the disadvantages of storing files in OneDrive? ›

The disadvantages of OneDrive are limited sharing options, limited file management and desktop synchronise settings. Limited Sharing Options: OneDrive's sharing options are limited compared to other cloud storage services, making it difficult to share files with non-Microsoft users.

Is Google Drive or OneDrive more secure? ›

Tips for choosing suitable cloud storage for your workplace

Both offer great features and enough storage at a competitive price. But, if we consider the security architecture, OneDrive provides extra security when compared to Google Drive.

What happens to files in OneDrive? ›

Change Local Storage and Sync Settings

Once your files are uploaded to OneDrive, they are deleted from storage by default. The files you decide to remove from local storage will continue to appear in File Explorer.

Is it safe to store in OneDrive? ›

Your content is stored securely

When you upload a file of any type to Google Drive, it is stored securely in our world-class data centers. Data is encrypted in-transit and at-rest.

Is OneDrive a secure way to save files? ›

As a cloud storage service, OneDrive has many other security features. Those include: Virus scanning on download for known threats - The Windows Defender anti-malware engine scans documents at download time for content matching an AV signature (updated hourly).

Is OneDrive a safe backup for files? ›

Overall, OneDrive is a decent cloud storage service for some of your files. If you aren't storing sensitive data and you make use of the personal vault, the risk may be worth the benefits. Plus, you can have multiple OneDrive accounts.

Can you use Gmail with OneDrive? ›

Save Emails to OneDrive is fully integrated with your Gmail email. A single click directly from your Gmail inbox saves emails straight to your OneDrive folder. You never have to download anything to your hard drive, and can enjoy the ease of a full Gmail-OneDrive integration.

What is the difference between OneDrive and my drive? ›

In short, Google Drive is better for independent users who store a normal amount of stuff. OneDrive makes more sense for businesses and teams that are doing heavy-duty storage or large-scale syncing.

What happens to my data if I cancel OneDrive? ›

All customer data—from user data to documents and email—is permanently deleted and is unrecoverable. At this point, you can't reactivate the subscription. However, as a global or billing admin, you can still access the admin center to manage other subscriptions, or to buy new subscriptions to meet your business needs.

Do files stay in OneDrive forever? ›

If you need to Restore a file after 90 days, you will need to contact your administrator. All files will be permanently deleted after 180 days and they cannot be restored.

Does deleting something from OneDrive delete from computer? ›

OneDrive uses two-way sync to sync files between OneDrive and the devices, so if you delete files from OneDrive, these files will be also deleted on the connected devices, like Windows computer, Mac, Android, iPhone/iPad, etc.

What is not allowed in OneDrive? ›

Invalid file or folder names

These names aren't allowed for files or folders: .lock, CON, PRN, AUX, NUL, COM0 - COM9, LPT0 - LPT9, _vti_, desktop.ini, any filename starting with ~$.

Should I store personal information on OneDrive? ›

Confidential data should NOT be stored or shared using OneDrive; see “Online File Storage Alternatives” listed below. Sensitive data may be stored and shared in OneDrive, but must be stored and shared in a secure manner (see “How to Use OneDrive Securely” below).

Does OneDrive save everything from my computer? ›

Effortless backup

Effortlessly back up your files to the cloud. Set up PC folder backup and OneDrive will automatically back up and sync all the files in your Desktop, Documents, and Pictures folders.

Top Articles
Latest Posts
Article information

Author: Laurine Ryan

Last Updated:

Views: 6255

Rating: 4.7 / 5 (57 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Laurine Ryan

Birthday: 1994-12-23

Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

Phone: +2366831109631

Job: Sales Producer

Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.