Encrypt Local OneDrive Files, but not in the Cloud

Brass Contributor

I have read about people interested in encrypting OneDrive files when they are stored in the in the "cloud". I have the opposite request. I want to be able to encrypt OneDrive files that are synced to my local computer, but not have them encrypted in the cloud. This way I can still use Word/Excel Online yet when  they are on my local machine they are secured.

 

I am thinking of cases where a laptop might be lost or stolen and someone may boot using other media and get access to files.  For a variatery of reasons we were shying away from using the built-in full disk encryption.

 

This would be something for Windows 7 and Windows 10.

 

What options are out there? 

 

thanks

 

Alan

 

4 Replies
any thoughts?

What are your reasons for not wanting to use BitLocker? We use it on all of our laptops in my organization and haven't had any problems with it, other than a couple needing their recovery keys after failing an upgrade.

 

 

Either way, you'll need to go with some form of full-disk encryption software (which you should be able to find several options for with a simple online search), otherwise if you use something that only encrypts individual files you'll sync an encrypted file back online, which you of course wouldn't then be able to open online.

OneDrive files are encrypted where they are stored in the cloud 'at rest' and in-transit, I'm not sure if that's what you are referring to.  I don't think encrypting the files in addition to that in the cloud is a thing people do*.  

 

This is completely transparent and non-configurable.  As has already been mentioned BitLocker would be the obvious candidate.  Otherwise, there are lots of different solutions on the market that you might have to evaluate.

 

*To add, there is Azure Information Protection that can go further with document level encryption via Azure RMS by the way.

so that it is. If you encrypt your local files and sync it to the cloud, they are also encrypted, you do not have any colaboration with others... Office Online will not work.

 

The ability for IRM is there, but unfortunatelly the Next Generation Sync client is not able to sync these IRM protected files (now). Microsoft is working on it.

I recommand, using Bitlocker for all users machines, and restrict sync to "only companys devices" unless IRM is working with sync.

 


@Cian Allner wrote:

OneDrive files are encrypted where they are stored in the cloud 'at rest' and in-transit, I'm not sure if that's what you are referring to.  I don't think encrypting the files in addition to that in the cloud is a thing people do*.  

 

This is completely transparent and non-configurable.  As has already been mentioned BitLocker would be the obvious candidate.  Otherwise, there are lots of different solutions on the market that you might have to evaluate.

 

*To add, there is Azure Information Protection that can go further with document level encryption via Azure RMS by the way.