Cyber Security News

OneDrive New Feature of Syncing Personal & Corporate Account is Rolling Out

Microsoft is set to roll out a new OneDrive feature that will prompt users to sync their personal Microsoft accounts with their corporate OneDrive accounts on Windows devices.

While designed to streamline file access, this update has raised significant security concerns among IT professionals, who warn it could create serious data exfiltration risks for organizations.

The feature, officially titled “Prompt to Add Personal Account to OneDrive Sync,” is associated with Microsoft 365 Roadmap ID 490064 and will begin rolling out in mid-June 2025, with completion expected by early July 2025.

According to Microsoft’s roadmap, the new feature will detect when users are signed into a personal Microsoft account on a Windows device while actively using their corporate OneDrive. It will then prompt them to also sign into OneDrive with their personal account.

OneDrive Syncing Personal & Corporate Account

Once users accept the prompt, they can access both personal and corporate OneDrive accounts on the same device without merging content.

The most concerning aspect for security professionals is that this functionality is enabled by default and requires no additional configuration once accepted.

It only appears if a personal account is already in use on the device, but security experts warn this represents a significant shift in Microsoft’s approach to separating personal and business data on corporate devices.

“If a user clicks ‘Yes’—and if IT hasn’t proactively locked this down, they’re free to copy files from their business OneDrive into their personal OneDrive account. From there, they can share anything with anyone. There is no logging, no control, and no corporate restrictions,” noted one security professional in an analysis of the feature.

At Cybersecurity News, we have already raised concerns that automatic syncing may bypass established security protocols. This process often lacks the necessary controls, logging mechanisms, and corporate policies that usually regulate the synchronization of personal accounts on business devices.

As a result, it creates a potential risk for both unintentional and malicious data transfers outside of corporate environments.

IT administrators have two primary options to mitigate this risk. They can deploy the DisableNewAccountDetection policy, which suppresses the prompts but still allows users to manually configure personal accounts if desired.

Alternatively, organizations that have previously restricted personal account usage with the DisablePersonalSync policy will not see the prompt at all.

Security professional Steven Lim has reportedly created a Microsoft Defender XDR custom detection KQL query to identify and flag instances where personal OneDrive accounts may have been added to corporate endpoints, providing an additional layer of monitoring for concerned organizations.

“Personal data doesn’t belong on company devices in my opinion, so I recommend disabling the prompt before its rollout in the coming weeks,” advised one IT professional, recommending that administrators enable both policies to ensure users won’t sync personal OneDrives and won’t receive unnecessary prompts.

For organizations using Intune, the setting “Prevent users from syncing personal OneDrive accounts (user)” can be enabled, though some administrators recommend also implementing registry key changes for complete protection.

Microsoft recommends that organizations update any support documentation in preparation for this change. However, security experts strongly advise implementing preventative policies before the mid-June rollout to avoid what some describe as “a corporate data nightmare waiting to happen”.

Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago