Data handling and policy

Do users store business-critical information locally on their systems rather than on centralized storage?

This question decides whether rebuilding a compromised device is a routine action or a data loss event.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether business-critical information lives on individual machines rather than in centralised, backed-up storage. It is asking about actual practice, and the honest answer in most organisations is that some does.

Why it is underwritten

Locally stored data is unbacked, unclassified, and unrecoverable. In a ransomware event it is the data that cannot be restored. In a device loss it is the data whose disclosure cannot be scoped. In a departure it is the data that walks out. Carriers ask because it affects the recovery estimate and the notification exposure at the same time.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Whether data has been centralised is partly measurable through synchronisation coverage, which is a better indicator than policy.

PlatformWhere the setting livesWhat has to be true
Microsoft 365Known folder move coverage across the fleetThe proportion of devices with desktop, documents, and pictures redirected to synchronised storage
Microsoft 365OneDrive sync health and storage consumption per userSynchronisation actually working, since a stalled client leaves data local while appearing configured
Microsoft 365Endpoint data loss prevention and content discovery on devicesVisibility of sensitive content residing on endpoints
Microsoft 365Teams and SharePoint adoption for team contentShared work happening in shared places, which is the structural fix rather than a control
PracticeLine-of-business exports and local databasesWhether reporting exports and departmental databases live on workstations. Attested
Sync configured is not sync working

Redirection can be enabled by policy and stalled on a meaningful share of devices: a full disk, a broken credential, a file the client cannot handle. Those devices look compliant in the policy view and hold local-only data. Sync health reporting is the check that matters.

What a defensible yes requires

  • User folders are redirected to synchronised storage and the redirection is verified as working.
  • Team content lives in shared platforms rather than on individual machines.
  • Sync health is monitored, so stalled clients are identified and fixed.
  • Departmental exports and local databases are identified and migrated.
  • Local disks are encrypted, so whatever remains local is at least protected.

How this answer goes wrong

The organisation answers no because policy directs users to network locations. Discovery finds spreadsheets that run departmental processes, a reporting database on someone's workstation, and years of documents in local folders that were never redirected. The answer describes the intended design of a decade ago.

Frequently asked

Is any local storage acceptable?

Working copies are unavoidable and fine when the authoritative copy is central. The exposure is data that exists only locally.

How do we find local-only data?

Sync health reporting shows where redirection is failing, and endpoint content discovery shows what sensitive data sits on devices. Both are available and rarely run.

Does this affect the recovery time answer?

Yes. If user data is central, rebuilding devices is fast and safe. If it is local, every rebuild is a restore, which lengthens recovery considerably.

What about developers and engineers?

Source code should live in a repository and often does. Local build artefacts and datasets are a different matter and are worth including in the analysis.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture