Do users store business-critical information locally on their systems rather than on centralized storage?
This question decides whether rebuilding a compromised device is a routine action or a data loss event.
What the carrier is actually asking
The carrier is asking whether business-critical information lives on individual machines rather than in centralised, backed-up storage. It is asking about actual practice, and the honest answer in most organisations is that some does.
Why it is underwritten
Locally stored data is unbacked, unclassified, and unrecoverable. In a ransomware event it is the data that cannot be restored. In a device loss it is the data whose disclosure cannot be scoped. In a departure it is the data that walks out. Carriers ask because it affects the recovery estimate and the notification exposure at the same time.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Whether data has been centralised is partly measurable through synchronisation coverage, which is a better indicator than policy.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Microsoft 365 | Known folder move coverage across the fleet | The proportion of devices with desktop, documents, and pictures redirected to synchronised storage |
| Microsoft 365 | OneDrive sync health and storage consumption per user | Synchronisation actually working, since a stalled client leaves data local while appearing configured |
| Microsoft 365 | Endpoint data loss prevention and content discovery on devices | Visibility of sensitive content residing on endpoints |
| Microsoft 365 | Teams and SharePoint adoption for team content | Shared work happening in shared places, which is the structural fix rather than a control |
| Practice | Line-of-business exports and local databases | Whether reporting exports and departmental databases live on workstations. Attested |
Redirection can be enabled by policy and stalled on a meaningful share of devices: a full disk, a broken credential, a file the client cannot handle. Those devices look compliant in the policy view and hold local-only data. Sync health reporting is the check that matters.
What a defensible yes requires
- User folders are redirected to synchronised storage and the redirection is verified as working.
- Team content lives in shared platforms rather than on individual machines.
- Sync health is monitored, so stalled clients are identified and fixed.
- Departmental exports and local databases are identified and migrated.
- Local disks are encrypted, so whatever remains local is at least protected.
How this answer goes wrong
The organisation answers no because policy directs users to network locations. Discovery finds spreadsheets that run departmental processes, a reporting database on someone's workstation, and years of documents in local folders that were never redirected. The answer describes the intended design of a decade ago.
Frequently asked
Is any local storage acceptable?
Working copies are unavoidable and fine when the authoritative copy is central. The exposure is data that exists only locally.
How do we find local-only data?
Sync health reporting shows where redirection is failing, and endpoint content discovery shows what sensitive data sits on devices. Both are available and rarely run.
Does this affect the recovery time answer?
Yes. If user data is central, rebuilding devices is fast and safe. If it is local, every rebuild is a restore, which lengthens recovery considerably.
What about developers and engineers?
Source code should live in a repository and often does. Local build artefacts and datasets are a different matter and are worth including in the analysis.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture