Enable Personal OneDrive Users to Grant Secure, Revocable, Read-Only Access to Third-Party AI and Search Services

Unity Org 0 Reputation points
2026-06-17T08:29:21.1+00:00

Description

Personal OneDrive users should be able to grant secure, revocable, read-only and folder-scoped access to trusted third-party AI and search services.

The current absence of this capability limits how individuals can search and use their own files. It may also pressure users toward Microsoft 365 business products or business tenants merely to obtain stronger search and integration capabilities.

Personal consumers should not need to purchase or administer a business environment simply to authorise a trusted service to search selected personal folders.

Why this matters

Microsoft already supports user-directed file sharing and account connections in other contexts. Its privacy framework also recognises that users may direct Microsoft to share content with third-party services.

Privacy law does not impose a blanket prohibition on individuals authorising a trusted service to process selected personal information. A carefully designed permission model can operate consistently with privacy principles including:

  • purpose limitation;
  • transparency;
  • security;
  • data minimisation;
  • informed user control; and
  • revocability.

Privacy should protect users’ control over their information, rather than prevent users from securely authorising access to selected files.

What personal OneDrive currently lacks

Personal users need a permission framework that allows them to:

  • select particular folders;
  • grant read-only access;
  • authorise a specifically identified third-party service;
  • understand exactly what the service can access;
  • limit the permission to a stated purpose;
  • make access time-limited where desired; and
  • revoke access immediately.

This should not require conversion to, or administration of, a Microsoft business tenant.

Requested solution

Microsoft should provide personal OneDrive users with:

  1. Folder-scoped OAuth or equivalent permissions.
  2. Read-only permission options that do not expose the entire OneDrive account.
  3. Clear consent screens explaining precisely which folders and information will be accessible.
  4. A central dashboard showing:
    • which services have access;
      • which folders they can access;
        • when access was granted;
          • what permission level applies; and
            • how to revoke access.
            1. Optional time limits and automatic permission expiry.
            2. Technical support for trusted third-party AI and search services without requiring a Microsoft 365 business tenant.

Request for explanation

Microsoft should also explain whether the present limitation results from:

  • personal OneDrive architecture;
  • Microsoft Graph permissions;
  • security or privacy requirements;
  • third-party implementation choices;
  • commercial product segmentation; or
  • a combination of these factors.

I have identified no general legal barrier preventing Microsoft from offering a carefully scoped and user-controlled access model. If Microsoft considers such a barrier to exist, it should explain it clearly.

Providing this functionality would improve user autonomy, transparency and trust while maintaining appropriate privacy and security protections.Description

Personal OneDrive users should be able to grant secure, revocable, read-only and folder-scoped access to trusted third-party AI and search services.

The current absence of this capability limits how individuals can search and use their own files. It may also pressure users toward Microsoft 365 business products or business tenants merely to obtain stronger search and integration capabilities.

Personal consumers should not need to purchase or administer a business environment simply to authorise a trusted service to search selected personal folders.

Why this matters

Microsoft already supports user-directed file sharing and account connections in other contexts. Its privacy framework also recognises that users may direct Microsoft to share content with third-party services.

Privacy law does not impose a blanket prohibition on individuals authorising a trusted service to process selected personal information. A carefully designed permission model can operate consistently with privacy principles including:

  • purpose limitation;
  • transparency;
  • security;
  • data minimisation;
  • informed user control; and
  • revocability.

Privacy should protect users’ control over their information, rather than prevent users from securely authorising access to selected files.

What personal OneDrive currently lacks

Personal users need a permission framework that allows them to:

  • select particular folders;
  • grant read-only access;
  • authorise a specifically identified third-party service;
  • understand exactly what the service can access;
  • limit the permission to a stated purpose;
  • make access time-limited where desired; and
  • revoke access immediately.

This should not require conversion to, or administration of, a Microsoft business tenant.

Requested solution

Microsoft should provide personal OneDrive users with:

  1. Folder-scoped OAuth or equivalent permissions.
  2. Read-only permission options that do not expose the entire OneDrive account.
  3. Clear consent screens explaining precisely which folders and information will be accessible.
  4. A central dashboard showing:
    • which services have access;
      • which folders they can access;
        • when access was granted;
          • what permission level applies; and
            • how to revoke access.
            1. Optional time limits and automatic permission expiry.
            2. Technical support for trusted third-party AI and search services without requiring a Microsoft 365 business tenant.

Request for explanation

Microsoft should also explain whether the present limitation results from:

  • personal OneDrive architecture;
  • Microsoft Graph permissions;
  • security or privacy requirements;
  • third-party implementation choices;
  • commercial product segmentation; or
  • a combination of these factors.

I have identified no general legal barrier preventing Microsoft from offering a carefully scoped and user-controlled access model. If Microsoft considers such a barrier to exist, it should explain it clearly.

Providing this functionality would improve user autonomy, transparency and trust while maintaining appropriate privacy and security protections.

Microsoft Copilot | Other
0 comments No comments

3 answers

Sort by: Oldest
  1. AI answer

    2026-06-17T08:29:59.4566667+00:00

    Personal OneDrive already includes privacy-by-design controls and does not use customer data to train AI models. However, the provided context does not describe or document a folder-scoped, read-only, third‑party access model for personal OneDrive as requested, nor does it explain architectural or commercial reasons for its absence.

    The context confirms:

    • OneDrive privacy and security are governed by the Microsoft Privacy Statement, GDPR compliance, and Microsoft 365/SharePoint inheritance of privacy features.
    • Data remains within the customer tenant and is not used or transferred by Microsoft to train AI models.
    • For organizational OneDrive for Business, advanced search and privacy-sensitive scenarios (including private content) are handled via enterprise capabilities such as Microsoft 365 Search, eDiscovery, Microsoft Priva, and subject rights request APIs.

    The context does not provide:

    • Any description of folder-scoped OAuth or equivalent permissions for personal OneDrive.
    • Any documentation of a central dashboard for personal users to manage third‑party AI/search app access at a folder level.
    • Any explanation that the absence of such a feature is due to personal OneDrive architecture, Microsoft Graph design, security/privacy constraints, third‑party choices, or commercial segmentation.

    Because of this, there is no supported, documented answer in the context that can:

    • Confirm the existence of the requested feature for personal OneDrive.
    • Describe a supported workaround.
    • Provide Microsoft’s official rationale for the current limitations.

    For detailed explanations of how OneDrive handles privacy, security, and compliance today, including how data is stored and protected, refer to the OneDrive privacy and security overview. For organizational scenarios involving search over private content and privacy-compliant processing (for example, via eDiscovery or Priva subject rights requests), refer to the Microsoft 365 and Priva documentation in the references.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.