Office 365 OneDrive monitoring
5,000 employees. 5,000 sites nobody reviews. They are called OneDrive.
Every user carries a personal site with its own permissions, its own sharing links and its own sensitive files - and no governance review ever opens it. In a typical tenant, a large share of "anyone with the link" URLs were created from OneDrive, and the drives of people who left are still reachable for weeks after they are gone. 1Security treats every OneDrive as a site: listed, ranked by exposure, monitored for downloads and sharing, cleaned up behind a review window.
The problem
Personal drives, corporate data, zero reviews.
The convenient path for a working file is the personal drive: draft there, share from there, move on. Multiply that by every employee and OneDrive quietly becomes where a large share of live corporate content sits - budgets, contracts, exports of customer lists, the HR spreadsheet someone downloaded to "work on it at home".
Sharing from OneDrive works exactly like sharing from a site: anyone links, organization-wide links, direct external invitations. But while SharePoint sites get owners and reviews, personal drives get neither. A link created three years ago from a drive nobody audits is still a door today - sharing links have no expiry unless someone set one.
Then the owner leaves. The account is disabled, the license reclaimed - and the OneDrive, links included, stays reachable for a retention period of about 30 days before deletion. Nobody checks what it still exposes in those weeks. Across a year of leavers that is hundreds of drives with live links and nobody responsible for them.
In practice
The OneDrive review that never existed - in four passes.
How personal drives become governed territory in 1Security, in the first afternoon.
- 01
Split the tenant into sites and drives
The container filter on Files, Sites and links separates SharePoint sites from personal OneDrives in every view. Sort personal sites by storage, external users or sharing links and the top of the list is where the risk sits - typically a few dozen drives carry most of the exposure.
- 02
Sweep the links
Filter Files to personal drives with anyone links, links without a password or links past their expiration, then cross with sensitivity detections - 300+ detectors plus OCR, or imported Purview labels. In most tenants this shortlist is a few hundred files, and it is the shortlist that matters.
- 03
Audit the leavers
Filter Users to disabled or departed accounts and open the drives that still have active links or external users. Expire the links, revoke the grants and stage the cleanup - behind the 72-hour review window - while the retention window is still open, not after it closes.
- 04
Keep it watched
New sharing and downloads from personal drives show up in Activity logs within about ten minutes. Put a policy on "OneDrive anyone link plus sensitive content" and an activity alert on "more than 500 downloads in an hour" and the next incident is an email, not a discovery.
What makes it work
Drives are sites. Access is resolved to the file.
OneDrive governance falls out of three decisions the platform made early.
Every drive is a site
Personal OneDrives sit in the same inventory as SharePoint sites - members, links, storage, sensitive detections and activity, ranked by the same exposure logic.
Explore the feature →Lifecycle sees the leavers
Offboarding audits connect the departed account to everything it still exposes - including its drive and the links it created.
Explore the feature →Access, resolved to the file
Who can reach a file in a personal drive and through which grant - direct, link, group or inheritance - with revocation staged from the same view.
Explore the feature →
FAQ
Common questions.
Does this read the content of people's personal files?
Content is streamed through the sensitivity analysis and discarded. Only the detection type, match count and confidence are stored - never the matched values. 1Security holds a map of exposure, not a copy of anyone's drive.
Can we clean up links without breaking people's work?
Cleanup is staged, not instant. Proposed link removals wait in a review window - 72 hours by default - where they can be approved, rejected or routed to the drive owner, and every executed change is logged in Actions. Nothing disappears silently.
What happens to a OneDrive after the person leaves?
It stays for a retention period of about 30 days before deletion, and its links stay live in the meantime. In 1Security the drive and its links remain visible and attributable after the account is disabled, so you expire what it exposed instead of hoping retention gets there first. License reclaim rides the same flow.
Do we need E5 or a separate DLP product for this?
No. Read-only connection, standard Microsoft 365 licensing, no agent. Sensitivity detection is 1Security's own; if you already run Purview, its labels and detections are imported alongside.
Give the other half of your tenant its first review.
Connect read-only and filter to personal drives with anyone links and sensitive content - most teams have their shortlist within the first hour.
Or keep reviewing only the half that has meetings.