Description
Personal OneDrive users should be able to grant secure, revocable, read-only and folder-scoped access to trusted third-party AI and search services.
The current absence of this capability limits how individuals can search and use their own files. It may also pressure users toward Microsoft 365 business products or business tenants merely to obtain stronger search and integration capabilities.
Personal consumers should not need to purchase or administer a business environment simply to authorise a trusted service to search selected personal folders.
Why this matters
Microsoft already supports user-directed file sharing and account connections in other contexts. Its privacy framework also recognises that users may direct Microsoft to share content with third-party services.
Privacy law does not impose a blanket prohibition on individuals authorising a trusted service to process selected personal information. A carefully designed permission model can operate consistently with privacy principles including:
- purpose limitation;
- transparency;
- security;
- data minimisation;
- informed user control; and
- revocability.
Privacy should protect users’ control over their information, rather than prevent users from securely authorising access to selected files.
What personal OneDrive currently lacks
Personal users need a permission framework that allows them to:
- select particular folders;
- grant read-only access;
- authorise a specifically identified third-party service;
- understand exactly what the service can access;
- limit the permission to a stated purpose;
- make access time-limited where desired; and
- revoke access immediately.
This should not require conversion to, or administration of, a Microsoft business tenant.
Requested solution
Microsoft should provide personal OneDrive users with:
- Folder-scoped OAuth or equivalent permissions.
- Read-only permission options that do not expose the entire OneDrive account.
- Clear consent screens explaining precisely which folders and information will be accessible.
- A central dashboard showing:
- which services have access;
- which folders they can access;
- when access was granted;
- what permission level applies; and
- Optional time limits and automatic permission expiry.
- Technical support for trusted third-party AI and search services without requiring a Microsoft 365 business tenant.
Request for explanation
Microsoft should also explain whether the present limitation results from:
- personal OneDrive architecture;
- Microsoft Graph permissions;
- security or privacy requirements;
- third-party implementation choices;
- commercial product segmentation; or
- a combination of these factors.
I have identified no general legal barrier preventing Microsoft from offering a carefully scoped and user-controlled access model. If Microsoft considers such a barrier to exist, it should explain it clearly.
Providing this functionality would improve user autonomy, transparency and trust while maintaining appropriate privacy and security protections.Description
Personal OneDrive users should be able to grant secure, revocable, read-only and folder-scoped access to trusted third-party AI and search services.
The current absence of this capability limits how individuals can search and use their own files. It may also pressure users toward Microsoft 365 business products or business tenants merely to obtain stronger search and integration capabilities.
Personal consumers should not need to purchase or administer a business environment simply to authorise a trusted service to search selected personal folders.
Why this matters
Microsoft already supports user-directed file sharing and account connections in other contexts. Its privacy framework also recognises that users may direct Microsoft to share content with third-party services.
Privacy law does not impose a blanket prohibition on individuals authorising a trusted service to process selected personal information. A carefully designed permission model can operate consistently with privacy principles including:
- purpose limitation;
- transparency;
- security;
- data minimisation;
- informed user control; and
- revocability.
Privacy should protect users’ control over their information, rather than prevent users from securely authorising access to selected files.
What personal OneDrive currently lacks
Personal users need a permission framework that allows them to:
- select particular folders;
- grant read-only access;
- authorise a specifically identified third-party service;
- understand exactly what the service can access;
- limit the permission to a stated purpose;
- make access time-limited where desired; and
- revoke access immediately.
This should not require conversion to, or administration of, a Microsoft business tenant.
Requested solution
Microsoft should provide personal OneDrive users with:
- Folder-scoped OAuth or equivalent permissions.
- Read-only permission options that do not expose the entire OneDrive account.
- Clear consent screens explaining precisely which folders and information will be accessible.
- A central dashboard showing:
- which services have access;
- which folders they can access;
- when access was granted;
- what permission level applies; and
- Optional time limits and automatic permission expiry.
- Technical support for trusted third-party AI and search services without requiring a Microsoft 365 business tenant.
Request for explanation
Microsoft should also explain whether the present limitation results from:
- personal OneDrive architecture;
- Microsoft Graph permissions;
- security or privacy requirements;
- third-party implementation choices;
- commercial product segmentation; or
- a combination of these factors.
I have identified no general legal barrier preventing Microsoft from offering a carefully scoped and user-controlled access model. If Microsoft considers such a barrier to exist, it should explain it clearly.
Providing this functionality would improve user autonomy, transparency and trust while maintaining appropriate privacy and security protections.