OneDrive Security Guide

Microsoft OneDrive is a cloud storage service provided to the University community by Pitt Digital and may be used for the storage of Restricted data per the Data Risk Classification and Compliance Operating Standard.

While both Pitt Digital and Microsoft provide advanced protections for data stored in OneDrive, such as virus scanning, suspicious activity monitoring, ransomware detection, and service-level encryption, you have a shared responsibility to ensure that the information you choose to store in OneDrive remains protected, confidential, and compliant with applicable laws, regulations, and contractual agreements.

This guide aims to provide you with tips and guidance to ensure that your data remains safe and secure while taking advantage of the features and benefits OneDrive offers.

Quick Tips
Accessing OneDrive
Enable Multi-Factor Authentication (MFA)
Secure Your Devices
How to Share Files and Folders
Understand Sharing Permissions

When sharing content from OneDrive, you control what can and can’t be done with your data. There are generally three permissions options when sharing files and folders:

  • Can view – The default permissions when sharing.  Allows collaborators to view contents but they cannot make any changes.
  • Can edit – Allows collaborators to both view and make changes to contents of the shared file or folder. This includes editing file contents and uploading, downloading, or deleting files and folders from within a shared folder.
  • Can’t download – The same as Can view, but collaborators cannot download copies of the data from OneDrive to another location.

When creating links to share content from OneDrive, you also can specify who can use that link to access your data. In order of least restrictive to most restrictive, the available options for links are:

  • AnyoneAnyone with the link can access the contents of the shared file or folder. Users do not need to sign in or prove their identity before gaining access.
  • People in University of PittsburghAnyone with a University of Pittsburgh user account can access the shared content using the link. Users must sign in using their Pitt Passport username and password before gaining access.
  • Only people with existing access – Only those individuals who have already been given access to the content may use the link. These can be other Pitt users or external collaborators. A Pitt Passport account is not required.
  • People you choose – Only the individuals who’s email address is included in the Share dialog may use the link. These can be other Pitt users or external collaborators. A Pitt Passport account is not required.

IMPORTANT: When generating a link and choosing who can use it, you can also specify one of the permissions described earlier; Can view, Can edit, Can’t download. The chosen permissions will apply to everyone who can use the link.

For example, choosing to share a link with Anyone and selecting Can edit will allow anyone with the link to anonymously read, modify, delete, or download your data.

Understanding Permissions for Shared Folders

When sharing a folder from OneDrive it’s important to be aware that the chosen permissions are automatically inherited by all included files and sub folders. This will include any files and folders that may be created or uploaded in the future. Consider the following example:

  • My OneDrive
    • Folder 1
      • File 1
      • Folder 2
        • File 2    

Sharing Folder 1 and granting the Can edit permission means that those I’m sharing with will have Can edit permissions to Folder 1, File 1, Folder 2, and File 2.

Later, if I upload another file to Folder 2 named File 3, and because I have previously shared Folder 1, those same individuals will automatically be given Can edit permissions to File 3.

It is possible to break inheritance and give unique permissions to a folder or file within a folder. To determine this setting, go to the the folder's Permissions page (Manage Access > Advanced Settings).

  • To stop inheriting permissions, click Stop Inheriting Permissions in the toolbar.
  • To remove unique permissions and reset the folder to inherit permissions, click Delete unique permissions in the toolbar.
Reviewing and Managing Access
Print Article

Related Articles (2)

The following information outlines the steps necessary to store sensitive data in SharePoint securely. As a site owner, you are responsible for ensuring that configuration changes are made before any data is stored in SharePoint. A site owner also manages the groups and users that have access to their site(s).
The University of Pittsburgh takes seriously its commitment to protecting the privacy of its students, alumni, faculty, and staff and protecting the confidentiality, integrity, and availability of information essential to the University's academic and research mission. For that reason, we classify our information assets into risk categories to determine who may access the information and what minimum security precautions must be taken to protect it against unauthorized access.

Related Services / Offerings (1)

ONLINE FILE STORAGE Microsoft OneDrive for Business is a cloud storage solution where you can update, store, share, and sync your files from anywhere.