discoveranother Posted July 16, 2018 Posted July 16, 2018 Hi Guys Is office 365 Onedrive secure ? I'm against our customers storing sensitive data in Onedrive as I have heard it is not encrypted at rest ? Thanks
ShellfishClive Posted July 16, 2018 Posted July 16, 2018 Files are only encrypted during upload and I think download but they are not encrypted at rest. Microsoft have stated the reasons why this is, because decryption on shared files takes a while and sometimes can't be done by an end user etc.In all honesty once your files are on OneDrive they are pretty secure, short of a Microsoft data leak. 1
chaplic Posted July 17, 2018 Posted July 17, 2018 https://www.microsoft.com/en-us/trustcenter/security/encryption I believe files, at rest in Microsoft datacentres are​encrypted, but of course by the time they land on a client that may or may not be under your control, that's a different matter. Just having the file in onedrive, or having it on a local fileserver does not make it secure.
psydii Posted July 17, 2018 Posted July 17, 2018 OneDrive is a little ambiguous. https://support.office.com/en-us/article/data-encryption-in-onedrive-for-business-and-sharepoint-online-6501b5ef-6bf7-43df-b60d-f65781847d6c It is all bitlocker protected so if a drive from a decanter were removed the data would be inaccessible. On tenants built on the modern multi-tenant architecture individual files are also encrypted in the blob storage. So it follows if your tenant is not on "modern multi-tennant architecture" it is accessible by a MS tech with access to the vm hosting the volume on which the file is stored. Not sure what the demarkation point between host that are on the modern architecture and those that are not is.
free780 Posted July 17, 2018 Posted July 17, 2018 (edited) If you configure and pay for Windows Information Protection, files within OneDrive and SharePoint sites are encrypted where ever they go. Edited July 17, 2018 by free780
jmak Posted July 17, 2018 Posted July 17, 2018 If we assume that security through obscurity is not a good approach - the counter argument to saying that MS is more likely to be hacked because it's a big target, then your choice for storing data is: 1) Personal phone 2) USB flash drive 3) Laptop (encrypted or not) 4) Server you manage 5) Server managed by Microsoft's best experts working 24x7 to protect your data I know where I'd choose to put mine....
discoveranother Posted July 17, 2018 Author Posted July 17, 2018 Considering how many millions of users worldwide MUST be using Onedrive then they must feel it is secure for them.
free780 Posted July 18, 2018 Posted July 18, 2018 The thing to remember with Office 365 is yes it's free for education. But if you want data to be secure on any device you need EMS/AIP/WIP. Equally if you have 1:1 iPads etc you want a organisation sanctioned cloud storage available office 365 or gsuite. This appears the way things will go to per user (per FTE) licencing. Or you stop staff syncing to OneDrive on non-domain devices and stop email on personal devices.
jmak Posted July 18, 2018 Posted July 18, 2018 The thing to remember with Office 365 is yes it's free for education. But if you want data to be secure on any device you need EMS/AIP/WIP. Equally if you have 1:1 iPads etc you want a organisation sanctioned cloud storage available office 365 or gsuite. This appears the way things will go to per user (per FTE) licencing. Or you stop staff syncing to OneDrive on non-domain devices and stop email on personal devices.Agreed. WRT OP's original question, yes I think Office 365 is sufficiently secure (as is G Suite). The areas of greatest risk is where the end user has access to it, so that's where you need to have effective controls (technical and procedural).
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now