Browse all topics
SharePoint & OneDrive

OneDrive Personal Vault

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

What OneDrive Personal Vault is, how it works, why it exists only in consumer OneDrive and not in OneDrive for work or school — and what the equivalent protections are for sensitive files in a business tenant.

"Where's Personal Vault in our OneDrive?" is one of those questions that lands in every IT inbox eventually — usually from someone who uses OneDrive at home, saw the vault there, and wants the same locked folder for their HR files at work. The answer is that Personal Vault is a consumer OneDrive feature and does not exist in OneDrive for work or school, and that's not an oversight: business tenants have a different, more capable set of controls for the same problem. This guide explains what Personal Vault actually does, why it isn't in the business product, and what to point people at instead.

What Personal Vault is

In consumer OneDrive (the free tier and Microsoft 365 Personal/Family), Personal Vault is a special folder that requires a second verification step to open — Windows Hello, a fingerprint or face on mobile, a PIN, or a code sent to your phone or email — even when you're already signed in. It's designed for the handful of files you'd rather not have exposed if someone borrows your laptop or glances at your phone: passport scans, tax documents, insurance paperwork.

The mechanics:

  • Automatic locking. The vault relocks after a short period of inactivity — a few minutes on mobile, around twenty minutes on the web and on Windows by default — and on Windows the local copy is stored in a BitLocker-encrypted area of the drive regardless of whether the rest of the disk uses BitLocker.
  • Restricted sharing. Files in the vault can't be shared. Move a file out to share it.
  • Mobile scanning. The OneDrive mobile app can scan documents straight into the vault.
  • Storage limits. On the free and basic tiers the vault holds only a small number of files (three at launch); Microsoft 365 Personal and Family subscribers can store as much as their quota allows.
  • Clients. Windows 10 and 11 (via the sync client), OneDrive web, and the iOS and Android apps. Not on Mac.

It's a good feature for what it is: a low-friction "extra lock" for a personal account. It isn't encryption you control — Microsoft still holds the keys, as with the rest of OneDrive — and it isn't a security boundary against a compromised Microsoft account with MFA already bypassed.

Why it isn't in OneDrive for work or school

Personal Vault solves a shared-device, single-consumer-account problem: one person, several devices, family members around. Business tenants face a different problem — files belong to the organisation, access is governed centrally, and "a folder only I can open with a second factor" cuts across everything an admin needs: eDiscovery, legal hold, retention, DLP, and offboarding. A vault that IT can't open is a compliance liability, not a feature.

Microsoft has never shipped Personal Vault for business accounts, and the roadmap hasn't suggested it will. When a user asks for it, the real request is usually one of three things:

  1. "I don't want colleagues to see this" — a permissions question. Their OneDrive is already private by default; nothing in it is visible to anyone unless they share it.
  2. "I don't want this readable if my laptop is stolen" — a device encryption question. Business devices should have BitLocker (or FileVault) enforced through Intune, which protects everything on disk, not one folder.
  3. "This is really sensitive even within the company" — a classification question, and that's where sensitivity labels come in.

The business-tenant equivalents

Sensitivity labels with encryption. Apply a label like Highly Confidential – Only me or a scoped label that encrypts the file with Purview Information Protection. The file is encrypted at rest and in transit, it stays encrypted when downloaded or emailed, and access is controlled by identity rather than by location. This is stronger than Personal Vault in every respect except convenience, and it works across SharePoint, Teams, and Outlook too. Admins can still recover access through super-user rights for eDiscovery.

Conditional Access and MFA. The "second factor to open" experience is, in business terms, a Conditional Access policy: require MFA or a compliant device to access OneDrive at all, with sign-in frequency and session controls for unmanaged devices. That covers the whole account, which is what actually matters.

Device encryption via Intune. BitLocker on Windows, FileVault on Mac, enforced and reported. Personal Vault's BitLocker-protected folder is a subset of what a managed device already provides.

Data loss prevention. Rules that stop labelled or sensitive-information-type files being shared externally or downloaded to unmanaged devices — the "can't share from the vault" behaviour, applied by policy instead of by folder.

OneDrive sharing settings. If the worry is accidental oversharing, the tenant-level defaults (no "anyone" links, expiring links, external sharing restricted) address it for everyone rather than for one folder.

Personal use on the side. If someone genuinely wants a vault for personal documents, the answer is a personal Microsoft account with its own OneDrive, kept separate from work — which is also the right answer for keeping personal passports out of the corporate tenant's eDiscovery scope.

What to tell the user

"Personal Vault is a home-OneDrive feature. At work, your OneDrive is already private, your laptop is encrypted, and for anything genuinely sensitive use the Highly Confidential label — that encrypts the file itself, wherever it goes." Then check that those three things are actually true in your tenant, because the request is a useful prompt to confirm that BitLocker is enforced, labels are published, and OneDrive sharing defaults aren't "anyone with the link."

The absence of Personal Vault in the business product is a design decision, and a sound one. The controls that replace it are better — they're just spread across three admin centers instead of being one folder with a lock icon.

Further reading

Spot something wrong or want a topic covered? Send it through the contact form.