Skip to content
10 min read Recently reviewedBeginner

Understanding What IT Can See on Your Work Computer

Applies to: Company-owned Windows and Mac computers; Microsoft 365 (Outlook, Teams, OneDrive, SharePoint)
Article Type: Informational
Last Updated: 2026-07-29

Summary

This article gives you a straight answer to a question most people are uneasy about asking: what can your employer actually see on your work computer? It covers what is technically visible, what is routinely looked at, and what policy and law allow — three very different things — and closes with what to do about it.

Prerequisites

Instructions

1. Start With the Ownership Question

The work laptop and the Microsoft 365 account attached to it belong to your employer, the same way the desk and the phone on it do. Everything below follows from that single fact.

That does not mean you have no privacy at work — most countries give employees meaningful protection, and most employers have written rules limiting what they will look at. It does mean the honest baseline is this: treat anything created, stored, or typed on the work computer as company property that a person could read one day for a legitimate reason. Build your habits around that, and none of the sections below will ever surprise you.

2. Email and Teams Messages Are Company Records

This is the area people most often misunderstand.

  • Your mailbox is searchable across the organization. A compliance administrator using Microsoft Purview eDiscovery can search every mailbox in the tenant by keyword, date range, participant, or attachment — without opening Outlook and without your involvement.
  • Teams chats live in the same searchable store. Private one-to-one chats and channel messages are written to hidden folders in the participants' mailboxes. They are covered by the same searches.
  • Deleting does not mean deleted. Items you delete move to a recoverable area for a retention window your organization sets. If your mailbox is under a retention policy or a legal hold — common in finance, healthcare, and any company involved in litigation — a copy is preserved and remains findable no matter what you clear from your own view.
  • Editing or recalling a message does not erase the original. Teams keeps the edit history in the compliance record, and a recalled email is only withdrawn from mailboxes that have not read it.

Note: This is not surveillance — it is records management. Regulators and courts require organizations to be able to produce their own communications on demand, and the same machinery that satisfies a court order is the machinery that could read your message about lunch.

3. Files in OneDrive and SharePoint Are Visible to Administrators

Cloud storage on a work account is administered storage.

  • A OneDrive administrator can grant themselves access to your work OneDrive. They do not need your password. This is how a company retrieves work files when someone is on long-term leave or has left.
  • SharePoint site owners and administrators see everything in their sites, including files you thought were tucked away in a subfolder.
  • Version history preserves your earlier drafts. Replacing a document does not remove what it said before — every prior version stays available for the retention period.
  • Data loss prevention policies scan file contents. Rules that look for card numbers, ID numbers, or confidential markings run over your files and can flag or block sharing. See Understanding DLP: Why Can't I Send This Email?.

The practical consequence: personal documents stored in a work OneDrive are readable by your employer and are removed when your account is closed. That is where personal tax returns and family photos are lost at offboarding.

4. Browsing Through the Company Network or VPN Can Be Logged

Where your traffic travels decides who can see it.

  • On the office network or the company VPN, requests pass through a web filter or proxy that records the sites requested, the time, and the device or account that asked. Blocked attempts are recorded too — an accidental click on a shopping link is a log line and nothing more.
  • Many organizations inspect encrypted traffic on managed devices, which means the padlock in the address bar does not hide the destination from the company's own filter.
  • Signing in to Edge or Chrome with your work profile syncs history, favourites, and saved passwords into your work account rather than your personal one. Administrators do not read your saved passwords, but that data now lives under company control.
  • Disconnecting the VPN moves your traffic off the company network, but the laptop still belongs to your employer and still carries whatever management software is installed on it.
  • An Incognito or InPrivate window changes none of the above. It keeps the visit out of your own history on that computer; the web filter and the company DNS resolver record the request either way. This is the most common misunderstanding on the whole subject — see Understanding the Incognito Mode Myth.

5. Installed Software, Device Inventory, and Audit Logs

Three quieter categories that are collected continuously and looked at rarely.

What is collectedWhat it showsWhy it exists
Device inventoryModel, serial number, operating system build, disk encryption state, last check-in timeAsset tracking and security compliance
Installed softwareEvery application on the machine, with versionsLicence counts and finding unpatched software
Sign-in logsWhen you signed in, from which app, IP address, and rough locationDetecting account compromise
Activity audit logsFiles opened, downloaded, shared, or deleted; mailboxes opened by someone other than the owner; administrator actionsInvestigations and regulatory audits

Two things are worth pulling out of that table. First, administrator access to your mailbox or OneDrive is itself recorded — the audit log captures the administrator's name, the time, and what was opened, which is exactly what an auditor asks for. Second, you can see your own sign-in history without asking anyone: see How to Check Your Sign-In Activity in Microsoft 365.

What is not standard equipment: keystroke logging, silent screenshots, and webcam access are not built into Microsoft 365. Some employers deploy separate monitoring software that does those things, and in most jurisdictions they are required to tell you when they do. If nobody has told you, it is reasonable to assume it is not running — and reasonable to ask.

6. Possible, Routine, and Permitted Are Three Different Things

Nearly every anxious conversation about workplace monitoring collapses these three, so separate them.

  • Technically possible is a long list. Most of section 2 through 5 sits here.
  • Routinely done is a very short list: automated security alerts, licence and patch reporting, and blocked-site counts. Nobody on the help desk has the hours to read your mail, and nothing in their daily work would surface it if they wanted to.
  • Permitted is narrower still. Reading an individual's mailbox or files normally needs a documented request from HR, Legal, or a security investigation, an approver who is not the requester, and a record of what was accessed. In much of Europe, works councils and data protection law add consultation requirements on top; several US states require written notice before electronic monitoring.

The useful mental model is a hotel: staff hold a master key to your room, they are permitted to use it for cleaning and emergencies, there is a record of every entry, and using it to read your diary would cost someone their job. The key exists. That is not the same as it being used.

7. Keep Personal Life Off the Work Device — and Read the Policy

None of this requires anxiety. It requires one habit and one document.

The habit: keep personal matters on personal equipment.

  1. Do personal email, banking, medical, and job hunting on your own device, over your own connection. This single rule removes almost every real risk.
  2. Keep personal files out of work OneDrive and work SharePoint. Move anything already there to personal storage now rather than during your notice period. See Understanding What to Do When You Leave or Change Jobs — IT Offboarding Checklist.
  3. Do not sign a personal browser profile in to the work computer, and do not save personal passwords in the work browser profile. If you already have, remove them from the browser's saved passwords list and change anything sensitive from a personal device.
  4. Use your phone on cellular data for personal calls and messages, rather than the office Wi-Fi.

The document: your acceptable use policy. Every employer that monitors anything has one, and you almost certainly accepted it at your first sign-in without reading it. Look in the HR section of the intranet, in your onboarding pack, or in the employee handbook. If you cannot find it, send HR this: "Please send me the acceptable use policy and any workplace monitoring notice that applies to my work computer." That request is routine, it is your right in most jurisdictions, and the answer tells you exactly where the line sits at your company rather than in general.

Troubleshooting

INFO

Nothing in this article is unique to Microsoft 365. Google Workspace, Slack, Zoom, and every other business platform have equivalent administrator access, retention, and audit features, because the same regulations require them. Changing tools does not change the answer.

Symptom / ErrorPotential CauseSolution
You deleted an email and want it permanently goneRetention policy or legal hold preserves a copyDeletion from your view is the limit of your control. Ask HR or Legal about the retention schedule that applies to your mailbox.
Personal photos and documents sit in your work OneDrivePersonal files on company storageCopy them to personal storage and delete the work copies now. Accounts are closed on the last working day, often without warning.
You clicked a blocked website by accidentThe web filter logged the requestBlocked requests are counted, not investigated. No action needed.
You want to know exactly what your employer monitorsThe policy has never been readSend HR: "Please send me the acceptable use policy and workplace monitoring notice for my device."
Personal passwords are saved in the work browserA personal account was signed in to the work profileRemove them from the browser's saved passwords list, then change those passwords from a personal device.
You suspect your mailbox has been opened by someone elseDelegated access or an investigationCheck your own sign-in and mailbox activity first, then ask HR: "Has non-owner access been granted to my mailbox, and under what process?"