Microsoft OneDrive Security Update: What MSPs Need to Know
Summary:
Microsoft's June 2025 OneDrive update introduced a "Prompt to Add Personal Account to OneDrive Sync" feature that lets hybrid-device users merge personal and corporate OneDrive accounts with a single click and no admin approval, creating potential security risks. MSPs can block it entirely with the DisablePersonalSync policy, or just disable the prompt with DisableNewAccountDetection. Best practices include monitoring OneDrive activity, communicating changes to end users, and reviewing security baselines as Microsoft rolls out cloud updates.
|
What you'll Learn |
|
|
Benefits for MSPs |
|
|
Required Next Steps |
|
In a June 2025 software update, Microsoft introduced a new feature allowing users on hybrid devices to sync their personal and professional OneDrive files.
This feature introduced several new data exposure risks that Microsoft tenant managers will need to take immediate action on.
Read on to learn what your MSP can do to push updates across your tenant base efficiently and mitigate the potential risks of this OneDrive sync feature.
At a Glance
- Feature name: "Prompt to Add Personal Account to OneDrive Sync"
- Release: June 2025
- Applies to: hybrid devices with both personal and corporate Microsoft accounts
The new feature, explained
The feature, officially titled "Prompt to Add Personal Account to OneDrive Sync," detects whether personal accounts are being used on business devices. If so, the user will be sent a single prompt, providing the option to synchronize both accounts. If accepted, synchronization begins with no further action or admin approval required.
The risks
The feature makes it easy for employees—inadvertently or otherwise—to synchronize their personal files with their corporate OneDrive. The risks here are multiple, including:
- The risk of transferring sensitive business files to personal accounts that lack corporate-grade protections
- The risk of disrupting corporate audit trails, with personal folders that do not fall under company jurisdiction
- The risk of exposing sensitive corporate data to third parties
- The risk of breaking regulatory compliance
Preparation and response
Microsoft admins can manage the threat using the following OneDrive policies:
- 'DisablePersonalSync', which disables personal OneDrive synchronization entirely and is considered the most effective defense.
- 'DisableNewAccountDetection', which disables the synchronization prompt, while still allowing for personal OneDrive access on company devices.
Additionally, some ongoing best practices include:
- Monitoring OneDrive activity, using Microsoft 365's activity explorer to identify attempted syncs or other unexpected data movements.
- Communicating any changes to end users, explaining any associated risks, necessary security updates or changes to processes.
- Regularly reviewing known Cloud service updates and updating security baselines accordingly.
With inforcer, MSPs get a single-pane view of every tenant they manage and can push major policy changes to multiple tenants within minutes. To find out more, book a demo below:
Scope and Limitation Statement
inforcer's 365 Manager lets MSPs push OneDrive sync policies (DisablePersonalSync, DisableNewAccountDetection) across managed tenants from one place. It doesn't retroactively remove files already synced to a personal account before the policy was applied, doesn't monitor personal OneDrive accounts themselves (only the corporate tenant), and doesn't replace a broader DLP or data classification strategy for other exfiltration paths.
The new feature, explained
The feature, officially titled “Prompt to Add Personal Account to OneDrive Sync,” detects if personal accounts are being used on business devices. If so, the user will be sent a single prompt, providing the option to synchronize both accounts. If accepted, synchronization begins with no further action or admin approval required.
The risks
The feature makes it easy for employees - inadvertently or otherwise - to synchronize their personal files with their corporate OneDrive. The risks here are multiple, including:
- The risk of transferring sensitive business files to personal accounts that lack corporate-grade protections
- The risk of disrupting corporate audit trails, with personal folders that do not fall under company jurisdiction
- The risk of exposing sensitive corporate data to third parties
- The risk of breaking regulatory compliance
Preparation and response
Microsoft admins can manage the threat using the following OneDrive policies:
- ‘DisablePersonalSync’, which disables personal OneDrive synchronization entirely and is considered the most effective defense.
- ‘DisableNewAccountDetection’, which disables the synchronization prompt, while still allowing for personal OneDrive access on company devices.
Additionally, some ongoing best practices include:
- Monitoring OneDrive activity, using Microsoft 365’s activity explorer to identify attempted syncs or other unexpected data movements.
- Communicating any changes to end users, explaining any associated risks, necessary security updates or changes to processes.
- Regularly reviewing known Cloud service updates and updating security baselines accordingly.
With inforcer, MSPs can push major policy changes to multiple tenants within minutes. To find out more, book a demo below:
FAQs
What is Microsoft's new OneDrive personal account sync feature?
Officially called "Prompt to Add Personal Account to OneDrive Sync," it detects when a personal Microsoft account is being used on a business device and offers the user a one-click prompt to sync both accounts — no admin approval required if accepted.
What are the security risks of OneDrive personal-work sync?
It creates several risks: sensitive business files can end up in a personal account without corporate-grade protections, personal folders fall outside company audit trails, corporate data can be exposed to third parties, and it can break regulatory compliance.
How do I stop OneDrive from syncing personal and work accounts?
The 'DisablePersonalSync' policy is the most effective option — it disables personal OneDrive synchronization entirely. 'DisableNewAccountDetection' is a lighter option that disables the sync prompt while still allowing personal OneDrive access on company devices.
When does this OneDrive update roll out?
The feature was scheduled for a June software update at the time of writing — MSPs should confirm current rollout status for their tenants' update channel.
Should I block personal OneDrive sync for all customers, or just some?
There's no one-size-fits-all answer: DisablePersonalSync is the most effective defense, but MSPs should weigh it against legitimate business cases for personal-device flexibility on a customer-by-customer basis.
How can inforcer help MSPs respond to this OneDrive update?
inforcer's 365 Manager lets MSPs push major policy changes like DisablePersonalSync across multiple tenants within minutes, rather than configuring each tenant's OneDrive settings individually.
Share this
You may also like
These related stories

How to Win More Business by Becoming a Microsoft MSP

What Microsoft's Copilot Specialization Means for MSPs
