How secure is OneDrive? (2024)

If you’re using OneDrive, you’re using Microsoft’s service to upload and share your files in their cloud. In this article, we’ll examine which data protection and security measures Microsoft implements for its cloud service.

Is OneDrive secure?

Microsoft has stated that they use end-to-end encryption with AES 256-bit standard for uploads, downloads and backups.

They also add another layer of security to OneDrive with two-factor authentication and the SSL/TLS encryption standard. Despite offering rather robust data security through good encryption, one can’t completely close out the possibility of third parties accessing data. Microsoft does not offer zero-knowledge encryption, giving Microsoft developers and the U.S. government, if needed; access to data stored in OneDrive.

What is OneDrive?

With OneDrive, you can store and organize your files, documents and other types of data (e.g., contacts, notes, passwords or photos) in Microsoft’s cloud. OneDrive is available for all Windows systems, but you need a Microsoft account to use it. Anyone who uses Microsoft 365 automatically has access to OneDrive.

You can choose to synchronize your OneDrive files across all your devices or for selected apps and devices only. You can also create automatic backups and collaborate with others on the files by using sharing options. OneDrive has another advantage: It comes with 5 GB of free cloud storage.

How is OneDrive encrypted?

Detailed information about Microsoft’s security measures for OneDrive can be found on Microsoft’s website. Microsoft uses the AES 256-bit encryption standard for data protection and security. It would take several billion years to crack such an encryption, even with a supercomputer. AES 256-bit is an encryption method that is sufficient enough to protect your data against large-scale brute-force attacks. For additional security and encryption during data transfer between client and server, Microsoft uses the TLS encryption standard as well. However, Microsoft doesn’t offer zero-knowledge encryption, meaning that the encryption key still stays in Microsoft’s hands.

Data access rights in OneDrive

As a OneDrive user, you still have considerable power when determining who can access your OneDrive files. Similar to Google Drive, OneDrive gives you the ability to grant reading, viewing and editing rights to people. You can do this via the Share menu for each of your folders or files. Once you have selected a specific person or group of people, you can provide access to the document via a shareable link or by sending an email. You can edit or delete any of these right at any time.

While Microsoft does potentially have access to your data in OneDrive, the company has emphasized that zero standing access means their developers can only access your data in exceptional cases. Such instances require explicit permission and are carried out under increased security and maintenance requirements.

One exception, however, applies to U.S. governmental agencies. As an American company, Microsoft is legally required to grant access to OneDrive data if a U.S. authority has a legitimate request. Laws such as the Cloud Act, the Patriot Act and the Foreign Intelligence Surveillance Act (FISA) give authorities the right to view and collect data of private citizens. This, however, is a rather rare occurrence.

OneDrive and the Cloud Act

The Cloud Act was passed in 2018 and significantly expands the rights of U.S. authorities to monitor their citizens as well as all companies operating within its borders. U.S. companies like Microsoft are required by law to share data with governmental agencies, even if the data is located on servers abroad. In order to access such data, the U.S. government needs to have a warrant. There are some rare occasions though where a warrant or a subpoena is not required.

These new, wider-reaching surveillance rights have caused concern in Europe. In 2020, the European Court of Justice declared the EU-U.S. Privacy Shield invalid, as the U.S. no longer meets European data protection standards. Previously, the Privacy Shield ensured a secure transfer of data from the EU to the U.S. It has yet (as of November 2022) to be replaced by any new legislation.

Certain states such as California and Virginia have passed their own data privacy acts that compel any companies offering services to their residents to comply with their data sovereignty laws. If you live in one of these states, your data is better protected than in states without such laws.

How secure is OneDrive against cyberattacks?

Although Microsoft OneDrive is not perfect, it still offers solid, reliable data security, especially if you’re using their cloud storage service for personal files or to back up data that isn’t mission critical. Companies should opt for the storage service OneDrive for Business.

OneDrive offers the following protection measures against cyber-attacks:

  • Password protection with a secure password
  • Two-factor authentication
  • AES 256-bit encryption
  • TLS encryption
  • Zero standing access
  • Network protection through isolated networks and firewalls
  • Mobile encryption of data with the OneDrive app
  • Account recovery (using email, phone number or security question)
  • Account notifications for suspicious logins
  • Spam filtering for OneDrive mail and virus scanning through Microsoft Defender
  • Ransomware protection (with Microsoft 365)
  • Personal OneDrive vault
  • Highly secure data centers
  • Automatic backups
  • Synchronization of data with connected devices
  • Automatically scanning updates for malware or illegal content
  • End-to-end encryption for backups, uploads and downloads

Where are OneDrive servers located?

Microsoft hosts their data in data centers in the United States, Asia and the European Union. You can see where your data is hosted in the settings of Microsoft Office 365. The data of OneDrive for Business customers located in the U.S. is hosted in one of four different locations within the U.S. It’s not possible to choose a specific data center for storing your company’s data.

The European Union’s data privacy law, the GDPR, legislates high standards of data privacy and security. Cloud storage providers located in Germany and Switzerland are among the most secure in the world.

Tip

Want more protection for your data than provided under U.S. law? Need to be compliant with GDPR requirements in the European Union? HiDrive cloud storage from IONOS is a viable option. Your data will be fully encrypted and stored securely in our certified data centers in the U.S. and Europe You can also choose the location of the data center to ensure GDPR compliance, if needed.

Is OneDrive compliant with the GDPR?

If you do business in the EU, you need to comply with the GDPR when storing and using customer data. Since OneDrive can transfer data to servers located in the U.S. without the Privacy Shield agreement as well as to servers in non-EU countries, OneDrive is not considered compliant with the GDPR. Furthermore, OneDrive terms and conditions grant Microsoft the right to use stored data, meaning GDPR-compliant data processing is not guaranteed.

Companies that use OneDrive for using or storing data from EU customers, employees or other stakeholders or partners, must provide the following information in their privacy policy:

  • Why is OneDrive used for storing data?
  • What is the legal basis for storing and processing the data?
  • Has a contract for collecting, processing and using the data been made with Microsoft?
  • How can individuals contest data collection and processing in OneDrive?
  • Where can users find Microsoft’s regulations regarding data usage and protection?

Furthermore, in accordance with Article 28 of the GDPR, companies must also make a written contract with Microsoft for data processing, collection and use if data is stored in OneDrive for business purposes. The following aspects must be defined:

  • What personal data does Microsoft receive?
  • Why is the data being passed on to Microsoft?
  • How long does Microsoft store the data?
  • What rights, obligations and disclaimers apply?

Is OneDrive secure for business and compliance?

Microsoft takes a lot of precautions in making OneDrive secure for business data. Not only do they offer two-factor authentication, fully encrypt data in transit as well as in rest, and store data in multiple, highly secured data centers, they also monitor your account for suspicious activity and logins, and alert you of account tampering and possible malware attacks.

In order to improve security, Microsoft scans OneDrive uploads, such as documents and photos, for malware and illegal content. They don’t, however, give any further explanation on how they conduct such scans and analysis.

Even though Microsoft does a lot to secure data, there is also always the chance of human error. It’s important that your company establishes and promotes behavior that ensures your company’s data is secure. All necessary OneDrive security settings should be enabled, and employees should be trained on privacy best practices. Below are some examples:

  • Set up two-factor authentication and enable it by default
  • Create a strong password with a random combination of numbers, symbols, and lowercase and capital letters. If possible, instruct your employees to change their passwords on a regular basis.
  • Enable encryption if OneDrive mobile apps are used
  • Be careful when granting access to documents, especially if you need to do this for people outside of your organization. Double-check emails, use permissions and check that the shared files and folders are the ones you want to share. OneDrive admins can further define default settings and reduce sharing rights for an added layer of security.
  • Best practices for data safety should be easy to access and regularly updated
  • Update OneDrive and malware systems regularly

Although you may not need to adhere to the GDPR with OneDrive business data, it’s still important for business compliance purposes to outline how you use Microsoft OneDrive to collect and process data. Make sure to also include Microsoft’s clauses on how they process and use data as well as the links to documents explaining this in your privacy policy.

What are some alternatives to OneDrive?

If you still have doubts about Microsoft’s data protection measures and are wondering which cloud is the safest, you could take a look at German cloud providers. Providers with the highest level of data protection and GDPR-compliant server locations include IONOS with its secure HiDrive cloud storage, leitzcloud by vBoxx and Your Secure Cloud. There are plenty of OneDrive alternatives on the market. Conducting a comparison of cloud storages providers will give you an overview of the market and help you to choose the provider that fits your requirements best.

Was this article helpful?

How secure is OneDrive? (2024)

FAQs

How secure is OneDrive? ›

OneDrive offers strong security measures that compare favorably to other leading cloud storage providers. However, it is still vulnerable to common cloud service security issues, including weak passwords, data breaches, malware and viruses, insider threats, misconfiguration, DoS attacks, and lack of encryption.

Is OneDrive really secure? ›

Security monitoring systems and automation: OneDrive and Office 365 maintain robust, real-time security monitoring systems. Among other issues, these systems raise alerts for attempts to illicitly access customer data, or for attempts to illicitly transfer data out of our service.

How confidential is OneDrive? ›

The OneDrive library provided for you is typically protected from public viewing by default. Only you can access personal documents and media files that you store in it unless you explicitly share a folder of documents or a single document with other people in your organization for reviewing or co-editing.

What is a disadvantage of using OneDrive? ›

The disadvantages of OneDrive are limited sharing options, limited file management, and limited desktop synchronisation settings. Limited Sharing Options: OneDrive's sharing options are limited compared to other cloud storage services, making sharing files with non-Microsoft users difficult.

How safe is personal vault on OneDrive? ›

OneDrive Personal Vault provides an extra layer of security by using Two-Factor Authentication, which helps ensure only you can access your critical information. Microsoft 365 Basic, Personal, and Family subscribers previously could only store a small number of files in their Personal Vault.

Can hackers access OneDrive files? ›

Malware and viruses: Like many cloud services, OneDrive is vulnerable to malware and viruses, which can lead to data loss or theft.

Is OneDrive more secure than Google Drive? ›

OneDrive's advanced security features provide businesses with greater protection and control over their data, making it a preferred choice for organizations that prioritize security and compliance. Besides the previous factors, OneDrive is also stronger than Google Drive in terms of file sharing control.

Can I backup my entire PC to OneDrive? ›

You can back up your important folders (your Desktop, Documents, and Pictures folders) on your Windows PC with OneDrive PC folder backup, so they're protected and available on other devices.

Is OneDrive worth keeping? ›

However, if you are looking for a powerful ecosystem that can boost your productivity and collaboration, OneDrive is definitely worth checking out. Perhaps the most valuable addition is the Office 365 package, which comes standard in the Personal plan, along with a less impressive 1 TB of cloud storage.

Does using OneDrive slow down your computer? ›

OneDrive can slow down your computer over time if it is used excessively, which can also affect the performance of Windows. So in this article, we are going to discuss the reasons - Why OneDrive slows down your computer and also provide quick solutions to fix it. Table of Contents: Introduction to Microsoft OneDrive.

How do I make sure my OneDrive is private? ›

Review and adjust privacy settings for OneDrive files and folders
  1. In the left panel, select My Files.
  2. In the folder list under the heading Sharing, notice that folders or files are either Private or Shared. Private files are only accessible to you. Shared files are accessible to you and others.

What file types are not allowed in OneDrive? ›

Invalid file or folder names

These names aren't allowed for files or folders: .lock, CON, PRN, AUX, NUL, COM0 - COM9, LPT0 - LPT9, _vti_, desktop.ini, any filename starting with ~$.

Which is more secure, OneDrive or SharePoint? ›

While both Microsoft 365 and OneDrive offer document encryption to keep data safe from prying eyes, only SharePoint can offer the added security of a stand-alone server—but it requires your own IT professionals to host it on-premises.

Which cloud storage is most secure? ›

These are the six most secure cloud storage solutions:
  • IDrive: Best overall secure cloud storage solution.
  • pCloud: Best for extended storage functionalities.
  • OneDrive: Best for Microsoft systems integration.
  • Internxt: Best option for secure file sharing features.
  • Sync.com: Best for ease of use and administration.
Mar 21, 2024

Can OneDrive be tracked? ›

While you can't directly track downloads for personal accounts, there's a way to glean some information about shared links. Here's how: Utilizing the "Details" Pane for Insights: Locate the shared file and right-click on it. Select "Details" to access a panel displaying information about the link.

Can malware infect OneDrive? ›

Ransomware's entry points to a Microsoft 365 environment can occur through various vectors, such as phishing emails, attachments carrying malware, or compromised credentials. This could lead to the encryption of files in OneDrive, SharePoint, and Exchange Online, thus leaving them unavailable to users.

Top Articles
Building Your Financial Safety Net: How to Create and Maintain Cash Reserves | OneDigital
Get the facts on student loans
7 C's of Communication | The Effective Communication Checklist
Why Are Fuel Leaks A Problem Aceable
Noaa Charleston Wv
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
Free Atm For Emerald Card Near Me
Flixtor The Meg
Horoscopes and Astrology by Yasmin Boland - Yahoo Lifestyle
Alpha Kenny Buddy - Songs, Events and Music Stats | Viberate.com
Bloxburg Image Ids
Urinevlekken verwijderen: De meest effectieve methoden - Puurlv
Day Octopus | Hawaii Marine Life
Blue Ridge Now Mugshots Hendersonville Nc
Thotsbook Com
Amelia Bissoon Wedding
Enderal:Ausrüstung – Sureai
Craigslist Deming
Used Drum Kits Ebay
Conan Exiles Thrall Master Build: Best Attributes, Armor, Skills, More
Teenleaks Discord
Equibase | International Results
Gayla Glenn Harris County Texas Update
Pokemon Unbound Shiny Stone Location
Crossword Help - Find Missing Letters & Solve Clues
Craigs List Jonesboro Ar
Egusd Lunch Menu
Catchvideo Chrome Extension
Www.1Tamilmv.con
Flaky Fish Meat Rdr2
Att U Verse Outage Map
Truis Bank Near Me
Morlan Chevrolet Sikeston
Navigating change - the workplace of tomorrow - key takeaways
Roto-Rooter Plumbing and Drain Service hiring General Manager in Cincinnati Metropolitan Area | LinkedIn
Blue Beetle Movie Tickets and Showtimes Near Me | Regal
Babylon 2022 Showtimes Near Cinemark Downey And Xd
Nancy Pazelt Obituary
Easy Pigs in a Blanket Recipe - Emmandi's Kitchen
2700 Yen To Usd
About My Father Showtimes Near Amc Rockford 16
No Boundaries Pants For Men
Ds Cuts Saugus
56X40X25Cm
Enr 2100
Tommy Bahama Restaurant Bar & Store The Woodlands Menu
The Nikki Catsouras death - HERE the incredible photos | Horror Galore
Argus Leader Obits Today
Laura Houston Wbap
Diamond Spikes Worth Aj
Is Chanel West Coast Pregnant Due Date
Joe Bartosik Ms
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 6243

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.