Are users able to store data to the hard drive of portable computers or portable media devices?
Data on a laptop is data outside your backups, outside your access controls, and outside your visibility when someone leaves.
What the carrier is actually asking
The carrier is asking whether users can write corporate data to local drives and to removable media such as USB devices. It is asking about capability rather than about policy, because a policy without a technical control does not answer it.
Why it is underwritten
Locally stored data is not backed up, not covered by collaboration retention, and not recoverable after a device is lost or rebuilt. Removable media adds exfiltration risk from insiders and a delivery path for malware. Both create breach exposure that the organisation cannot scope, because it does not know what was on the device.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Endpoint data controls are configured in device management and are measurable, though the underlying behaviour is harder to observe than the policy.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Microsoft 365 | Endpoint data loss prevention policies | Policies restricting copy to removable media and to unmanaged locations, in enforce rather than audit mode |
| Microsoft 365 | Removable storage access control policy | USB storage blocked or restricted to encrypted, approved devices |
| Microsoft 365 | Known folder move to OneDrive | Desktop and documents redirected to synchronised storage, which is the practical way local data stops being local |
| Entra ID | Conditional Access session controls for unmanaged devices | Download blocked from unmanaged devices, so browser access does not become local storage |
| Microsoft 365 | Sensitivity labels with encryption applied to sensitive documents | Labelled content stays protected even when it does reach a local drive |
Blocking local storage outright creates friction and workarounds. Redirecting the folders people actually use into synchronised storage means the data is centrally held, backed up, and revocable, without anyone changing how they work. It answers this question and improves the recovery answers at the same time.
What a defensible yes requires
- Removable storage is blocked or restricted to encrypted, approved devices.
- User folders are redirected to synchronised cloud storage.
- Endpoint data loss prevention is in enforcement mode for sensitive content.
- Downloads from unmanaged devices are restricted.
- Full disk encryption covers whatever local data does exist.
How this answer goes wrong
Policy prohibits it and nothing enforces it. Or endpoint data loss prevention runs in audit mode indefinitely, generating reports that show exactly how much data is being copied to removable media and preventing none of it. Both answer yes to a question about capability by describing intent.
Frequently asked
Is blocking USB storage realistic?
For most office populations yes, with an exception process. It is far more disruptive in engineering, media, and field environments, where a restriction to encrypted approved devices is the workable middle ground.
Does folder redirection count as a control?
It is the most effective one available here, because it removes the behaviour rather than forbidding it, and it improves device rebuild and departure handling at the same time.
What about personal cloud storage?
It belongs in the same answer. Data loss prevention and web filtering should cover uploads to unmanaged cloud services, which is the modern version of the USB stick.
How does this affect breach scope?
Materially. If a lost device held local copies and you cannot say what they were, the notification analysis has to assume the worst case.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture