How Safe is Onedrive Against Ransomware Attack? (2024)

How Safe is Onedrive Against Ransomware Attack? (1)

A number of businesses of late have come to rely onOneDrive for Business as their sole means of endpoint data protection. With Microsoft 365 becoming widely prevalent, businesses are viewing OneDrive as ‘free’ endpoint backup. Some have even gone to the extent of discarding their commercial-grade endpoint backup solutions in favor of using OneDrive to save costs.

While OneDrive has several fine features to recommend it, one of the things it definitely is NOT is a backup solution.

And businesses that rely on OneDrive exclusively for data protection may end up finding this out the hard way. But for this blog post, let’s focus on ransomware.

Conventional wisdom now states that one of the bestdefenses against ransomwareis a reliable backup. Having a safe, secondary copy of your data means you don’t have to negotiate with the attacker while being held hostage. You can restore your data back on your terms and thus control your own destiny. The question is whether the data copy in OneDrive is adequate to protect you against ransomware.

The Problems

1. Exposure to ransomware

OneDrive is a sync solution that is designed to quickly replicate file changes on your endpoint system to the cloud. This means all modifications to files on the endpoint – good and bad. Changes, deletions, and alterations caused to files due to a ransomware attack can also be faithfully replicated to OneDrive without delay. So, as it turns out, your backup copy can be just as susceptible as your primary copy. Not a great defense against ransomware.

2. The Site Recycle Bin

But there is a somewhat better way. Remember that ransomware usually deletes the original files and creates a new substitute file with a mangled name and encrypted contents. So, a lot of the original files end up in the SharePoint site recycle bin. This bin has a 30-day clock ticking against every file that lands in it. So, assuming the recycle bin hasn’t been deleted by anyone in those 30 days, an individual user can restore their OneDrive to a previous time. In fact, Microsoft recently introduced a new feature called “Restore your OneDrive” which allows you to roll your OneDrive back to an earlier point in time – up to 30 days ago.

Now, remember, there’s no centralized way to do this for multiple users. You’ll have to get each of your affected business users to do this with their OneDrive accounts. So, imagine doing that with several hundred users, who are not necessarily technically savvy, racing against a 30-day clock.

3. The Site Collection Recycle Bin

If you miss this 30-day period (God forbid), for the next 63 days, these files get moved to the site collection recycle bin – which only a SharePoint Admin can access. At this point, individual users can’t do the OneDrive restores on their own.

The SharePoint Admin has to restore for them. Now, imagine going through this type of restore process for several hundred users with a 30 or 60-day deadline dangling over your head.

4. Ransomware continues to get better

Most important – all this assumes that your versions and the recycle bins are immune from theransomware attack. Ransomware authors continue to innovate each day, and the word is that there are new strains of ransomware designed to compromise the recycle bin(s) – which then naturally leaves the OneDrive user (or administrator) with no recourse but to negotiate with the ransomware attackers.

Do you have specific requirements or enterprise needs?

Email Us

What you can do

How Safe is Onedrive Against Ransomware Attack? (3)

1. Use a commercial-grade backup solution

If you are protecting endpoints, invest in a commercial-gradebackup solution. In my opinion, this is a no-brainer and is non-negotiable. Don’t try to cut corners by using OneDrive – it’s just not worth it.

2. Make sure your backups are immutable

Look for backup solutions that have invested time and effort in ensuring that they have an immutable copy of data. This data is typically not only encrypted and versioned; it is stored securely away to prevent tampering and to keep it insulated from changes that happen on the user endpoint. To learn more about immutable and tamper-proof backups, check out Parablu’s BluVault.

3. Ensure you can control retention times

Not only can many commercial-grade backup solutions go back in time to a previous copy of data (from before the ransomware attack), they also let you control the retention, which means you don’t have a pre-determined 30, 60, or 90-day clock looming when you already have your hands full recovering from a ransomware attack.

4. Make sure your restores are a breeze

And with solutions like BluVault, data recovery is simple. Select a device, folder, file, or even a file version. Click and walk away. Data is restored faithfully, including folder and sub-folder structure to the destination of your choice.

5. Look for centralized management

And you should be able to manage multiple users/devices – all from a centralized console. You may delegate users to do their own recovery if you wish – but you should still be able to see what they did, when they did it, whether they were successful – and how many users you still have left to go. There should be no guesswork.

Use a commercial-grade backup solution

If you still would like to use OneDrive to protect your users, that’s fine. But then, make sure to backup your OneDrive for Business data. Solutions like Parablu’s BluVault for Microsoft 365 offer cloud-cloud backups of your Microsoft 365 assets like Exchange Online and OneDrive for Business. Having frequent and reliable copies of your OneDrive data to an alternate cloud destination is a sure-fire way of defending yourself against a ransomware attack.

This way, if the OneDrive versions and the recycle bin fail you, you know you have a safe backup you can fall back to.

A sound backup strategy should be a critical part of every organization’s Information Technology plan, including user endpoints. With many employees now spread out and working from home, in unsecured and unsupervised environments, it is all the more important to ensure that their data has enterprise-class protection. Modern, enterprise-class backup solutions like Parablu’s BluVault can use your OneDrive storage securely to provide you with a commercial-grade backup solution – giving you the best of both worlds.

OneDrive for Business is a great business productivity tool designed to sync file data for immediate and easy accessibility. But businesses would be remiss in mistaking it for a backup and relying on it entirely for ransomware protection.

I hope this blog post has helped the reader understand the anatomy of the recovery process from OneDrive. Think through the ramifications of the decision you make regarding your endpoints – before you choose to use OneDrive exclusively.

Parablu’s BluVault is designed to enable robust data backup from user endpoints, SaaS workloads (Microsoft 365), and edge servers. Our patented integration with Microsoft 365 and OneDrive for Business also means that you can deploy BluVault without spending a penny for backup storage. Sound interesting?Reach out to usand learn more.

How Safe is Onedrive Against Ransomware Attack? (2024)

FAQs

How Safe is Onedrive Against Ransomware Attack? ›

Exposure to ransomware

Is OneDrive protected against ransomware? ›

SharePoint and OneDrive Protection have built in features that help protect against ransomware attacks. Versioning: As versioning retains a minimum of 500 versions of a file by default and can be configured to retain more, if the ransomware edits and encrypts a file, a previous version of the file can be recovered.

How safe is OneDrive from hackers? ›

Malware and viruses: Like many cloud services, OneDrive is vulnerable to malware and viruses, which can lead to data loss or theft.

Can OneDrive get malware? ›

When a malicious file is uploaded to OneDrive, the file is synced to the local machine before being marked as malware. After the file is marked as malware, the user can't open the synced file from their local machine.

How good is OneDrive security? ›

Is OneDrive secure? Microsoft has stated that they use end-to-end encryption with AES 256-bit standard for uploads, downloads and backups. They also add another layer of security to OneDrive with two-factor authentication and the SSL/TLS encryption standard.

What is a disadvantage of using OneDrive? ›

The disadvantages of OneDrive are limited sharing options, limited file management, and limited desktop synchronisation settings. Limited Sharing Options: OneDrive's sharing options are limited compared to other cloud storage services, making sharing files with non-Microsoft users difficult.

Can ransomware affect Microsoft 365? ›

Ransomware targeting Microsoft 365 operates much like any other ransomware but focuses on the unique aspects of the Microsoft 365 environment. Once the ransomware infiltrates your system, it spreads, encrypting files stored in OneDrive, SharePoint, and even emails in Outlook.

How secure is my OneDrive account? ›

OneDrive uses encryption to protect your data in transit and at rest, and also offers security features such as two-factor authentication, ransomware detection and recovery, and Personal Vault.

Is OneDrive more secure than Google Drive? ›

Tips for choosing suitable cloud storage for your workplace

Both offer great features and enough storage at a competitive price. But, if we consider the security architecture, OneDrive provides extra security when compared to Google Drive.

How to make OneDrive secure? ›

Two-Factor Authentication (2FA) in OneDrive
  1. Sign in to OneDrive.com using your Microsoft credentials.
  2. Enable Personal Vault (from Settings choose Personal Vault, then click Enable).
  3. Choose Two-Factor Authentication (2FA). For enhanced security, enabling your OneDrive Personal Vault requires 2FA. ...
  4. Enter your PIN.

How do I remove malware from OneDrive? ›

Delete the file (recommended)

To protect yourself, your computer, and your organization, the best option is to delete the file. From the OneDrive mobile app, your only option is to delete the file. Select the file you want to delete (on the mobile app, press and hold to select it). Select Delete.

Is OneDrive a secure cloud? ›

Encryption: OneDrive uses 256-bit AES encryption to protect your data in transit and at rest. This is a robust encryption method that is widely used to secure data.

How do I stop OneDrive from stealing my files? ›

Method 4: Stop and Hide OneDrive all together
  1. Open Microsoft OneDrive settings.
  2. In the Account tab, click “Choose folders”. ...
  3. In the Settings tab, uncheck “Let me use OneDrive to fetch any of my files on this PC”
  4. In AutoSave tab, uncheck all automatic save and update options.
  5. Click “o*k” to save changes.

Is OneDrive safe from hackers? ›

When data transits into the service from clients, and between datacenters, it's protected using transport layer security (TLS) encryption. We only permit secure access. We won't allow authenticated connections over HTTP, but instead redirect to HTTPS.

Should I care about OneDrive? ›

While OneDrive is certainly secure because of the strong encryption Microsoft applies on your data, there are still questions about how much privacy you can expect. Since Microsoft performs the encryption, they also hold the ability to decrypt data if required.

Is OneDrive safer than iCloud? ›

iCloud uses 128-bit AES encryption on all its files. Google Drive uses the same encryption along with two-step authentication for an added layer of security. OneDrive has strong security implemented in its system, such as file encryption, additional security information, and two-factor authentication.

Did SentinelOne detect OneDrive as ransomware? ›

SentinelOne's software did catch it, and raised a flag about the possibility of a ransomware attack. Unfortunately, it still didn't stop shadow copies from being deleted because the local OneDrive executable is on an allow list.

Does Microsoft 365 have virus protection? ›

Microsoft 365 Family and Microsoft 365 Personal give you advanced protection from viruses and cybercrime, tools to help keep your information secure and private, and ways to recover your files from malicious attacks.

Can ransomware spread through SharePoint? ›

Yes, ransomware can infect SharePoint.

SharePoint is a popular collaboration platform developed by Microsoft that allows users to store, organize, and share documents and other content. Like any other software or system, SharePoint is not immune to cyber threats, including ransomware.

Who is responsible for protecting Microsoft 365 data from malware? ›

Protection against malware is a shared responsibility. See Exchange Online Protection, Microsoft Defender for Office 365, and Shared ransomware protection for more information on how Microsoft 365 can help secure your data.

Top Articles
Half of Uniswap v3 Users Lose Money — Here's Why | HackerNoon
Pros and Cons of Tiny House Living
Omega Pizza-Roast Beef -Seafood Middleton Menu
Zabor Funeral Home Inc
Botanist Workbench Rs3
Songkick Detroit
Imbigswoo
Ktbs Payroll Login
Zoebaby222
Conduent Connect Feps Login
Keurig Refillable Pods Walmart
Craigslist Farm And Garden Cincinnati Ohio
Craigslist Blackshear Ga
Boston Gang Map
Icommerce Agent
Petco Vet Clinic Appointment
Directions To Cvs Pharmacy
Jordan Poyer Wiki
Deshuesadero El Pulpo
Airline Reception Meaning
Craiglist.nj
Delectable Birthday Dyes
Wbap Iheart
1964 Impala For Sale Craigslist
Syracuse Jr High Home Page
The Ultimate Guide to Obtaining Bark in Conan Exiles: Tips and Tricks for the Best Results
Southern Democrat vs. MAGA Republican: Why NC governor race is a defining contest for 2024
Minecraft Jar Google Drive
Newcardapply Com 21961
Serenity Of Lathrop - Manteca Photos
Unlock The Secrets Of "Skip The Game" Greensboro North Carolina
Pillowtalk Podcast Interview Turns Into 3Some
Usf Football Wiki
Mistress Elizabeth Nyc
Nearest Ups Office To Me
Spn-523318
Gfs Ordering Online
Lake Kingdom Moon 31
Bunkr Public Albums
The power of the NFL, its data, and the shift to CTV
Charli D'amelio Bj
Patricia And Aaron Toro
Craigslist Binghamton Cars And Trucks By Owner
25 Hotels TRULY CLOSEST to Woollett Aquatics Center, Irvine, CA
Bedbathandbeyond Flemington Nj
Oak Hill, Blue Owl Lead Record Finastra Private Credit Loan
Google Flights Missoula
Bluebird Valuation Appraiser Login
Superecchll
March 2023 Wincalendar
Southern Blotting: Principle, Steps, Applications | Microbe Online
Lux Nails & Spa
Latest Posts
Article information

Author: Msgr. Benton Quitzon

Last Updated:

Views: 6329

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Msgr. Benton Quitzon

Birthday: 2001-08-13

Address: 96487 Kris Cliff, Teresiafurt, WI 95201

Phone: +9418513585781

Job: Senior Designer

Hobby: Calligraphy, Rowing, Vacation, Geocaching, Web surfing, Electronics, Electronics

Introduction: My name is Msgr. Benton Quitzon, I am a comfortable, charming, thankful, happy, adventurous, handsome, precious person who loves writing and wants to share my knowledge and understanding with you.