Jump to content

Recommended Posts

Posted
Files are only encrypted during upload and I think download but they are not encrypted at rest. Microsoft have stated the reasons why this is, because decryption on shared files takes a while and sometimes can't be done by an end user etc.In all honesty once your files are on OneDrive they are pretty secure, short of a Microsoft data leak.
  • Thanks 1
Posted

OneDrive is a little ambiguous. https://support.office.com/en-us/article/data-encryption-in-onedrive-for-business-and-sharepoint-online-6501b5ef-6bf7-43df-b60d-f65781847d6c

 

It is all bitlocker protected so if a drive from a decanter were removed the data would be inaccessible.

 

On tenants built on the modern multi-tenant architecture individual files are also encrypted in the blob storage.

 

So it follows if your tenant is not on "modern multi-tennant architecture" it is accessible by a MS tech with access to the vm hosting the volume on which the file is stored.

 

Not sure what the demarkation point between host that are on the modern architecture and those that are not is.

Posted (edited)
If you configure and pay for Windows Information Protection, files within OneDrive and SharePoint sites are encrypted where ever they go. Edited by free780
Posted

If we assume that security through obscurity is not a good approach - the counter argument to saying that MS is more likely to be hacked because it's a big target, then your choice for storing data is:

 

1) Personal phone

2) USB flash drive

3) Laptop (encrypted or not)

4) Server you manage

5) Server managed by Microsoft's best experts working 24x7 to protect your data

 

I know where I'd choose to put mine....

Posted
The thing to remember with Office 365 is yes it's free for education. But if you want data to be secure on any device you need EMS/AIP/WIP. Equally if you have 1:1 iPads etc you want a organisation sanctioned cloud storage available office 365 or gsuite. This appears the way things will go to per user (per FTE) licencing. Or you stop staff syncing to OneDrive on non-domain devices and stop email on personal devices.
Posted
The thing to remember with Office 365 is yes it's free for education. But if you want data to be secure on any device you need EMS/AIP/WIP. Equally if you have 1:1 iPads etc you want a organisation sanctioned cloud storage available office 365 or gsuite. This appears the way things will go to per user (per FTE) licencing. Or you stop staff syncing to OneDrive on non-domain devices and stop email on personal devices.
Agreed. WRT OP's original question, yes I think Office 365 is sufficiently secure (as is G Suite). The areas of greatest risk is where the end user has access to it, so that's where you need to have effective controls (technical and procedural).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...