Appearance
Understanding What IT Can See on Your Work Computer
Applies to: Company-owned Windows and Mac computers; Microsoft 365 (Outlook, Teams, OneDrive, SharePoint)
Article Type: Informational
Last Updated: 2026-07-29
Summary
This article gives you a straight answer to a question most people are uneasy about asking: what can your employer actually see on your work computer? It covers what is technically visible, what is routinely looked at, and what policy and law allow — three very different things — and closes with what to do about it.
Prerequisites
- A work computer and a Microsoft 365 work account. No admin rights or technical background required.
- This article covers the work computer and your Microsoft 365 account. For a managed phone or tablet, see Understanding Company Portal, Device Management, and Your Privacy. For productivity metrics, see Understanding Microsoft Viva Insights: Can My Boss See My Activity?.
Instructions
1. Start With the Ownership Question
The work laptop and the Microsoft 365 account attached to it belong to your employer, the same way the desk and the phone on it do. Everything below follows from that single fact.
That does not mean you have no privacy at work — most countries give employees meaningful protection, and most employers have written rules limiting what they will look at. It does mean the honest baseline is this: treat anything created, stored, or typed on the work computer as company property that a person could read one day for a legitimate reason. Build your habits around that, and none of the sections below will ever surprise you.
2. Email and Teams Messages Are Company Records
This is the area people most often misunderstand.
- Your mailbox is searchable across the organization. A compliance administrator using Microsoft Purview eDiscovery can search every mailbox in the tenant by keyword, date range, participant, or attachment — without opening Outlook and without your involvement.
- Teams chats live in the same searchable store. Private one-to-one chats and channel messages are written to hidden folders in the participants' mailboxes. They are covered by the same searches.
- Deleting does not mean deleted. Items you delete move to a recoverable area for a retention window your organization sets. If your mailbox is under a retention policy or a legal hold — common in finance, healthcare, and any company involved in litigation — a copy is preserved and remains findable no matter what you clear from your own view.
- Editing or recalling a message does not erase the original. Teams keeps the edit history in the compliance record, and a recalled email is only withdrawn from mailboxes that have not read it.
Note: This is not surveillance — it is records management. Regulators and courts require organizations to be able to produce their own communications on demand, and the same machinery that satisfies a court order is the machinery that could read your message about lunch.
3. Files in OneDrive and SharePoint Are Visible to Administrators
Cloud storage on a work account is administered storage.
- A OneDrive administrator can grant themselves access to your work OneDrive. They do not need your password. This is how a company retrieves work files when someone is on long-term leave or has left.
- SharePoint site owners and administrators see everything in their sites, including files you thought were tucked away in a subfolder.
- Version history preserves your earlier drafts. Replacing a document does not remove what it said before — every prior version stays available for the retention period.
- Data loss prevention policies scan file contents. Rules that look for card numbers, ID numbers, or confidential markings run over your files and can flag or block sharing. See Understanding DLP: Why Can't I Send This Email?.
The practical consequence: personal documents stored in a work OneDrive are readable by your employer and are removed when your account is closed. That is where personal tax returns and family photos are lost at offboarding.
4. Browsing Through the Company Network or VPN Can Be Logged
Where your traffic travels decides who can see it.
- On the office network or the company VPN, requests pass through a web filter or proxy that records the sites requested, the time, and the device or account that asked. Blocked attempts are recorded too — an accidental click on a shopping link is a log line and nothing more.
- Many organizations inspect encrypted traffic on managed devices, which means the padlock in the address bar does not hide the destination from the company's own filter.
- Signing in to Edge or Chrome with your work profile syncs history, favourites, and saved passwords into your work account rather than your personal one. Administrators do not read your saved passwords, but that data now lives under company control.
- Disconnecting the VPN moves your traffic off the company network, but the laptop still belongs to your employer and still carries whatever management software is installed on it.
- An Incognito or InPrivate window changes none of the above. It keeps the visit out of your own history on that computer; the web filter and the company DNS resolver record the request either way. This is the most common misunderstanding on the whole subject — see Understanding the Incognito Mode Myth.
5. Installed Software, Device Inventory, and Audit Logs
Three quieter categories that are collected continuously and looked at rarely.
| What is collected | What it shows | Why it exists |
|---|---|---|
| Device inventory | Model, serial number, operating system build, disk encryption state, last check-in time | Asset tracking and security compliance |
| Installed software | Every application on the machine, with versions | Licence counts and finding unpatched software |
| Sign-in logs | When you signed in, from which app, IP address, and rough location | Detecting account compromise |
| Activity audit logs | Files opened, downloaded, shared, or deleted; mailboxes opened by someone other than the owner; administrator actions | Investigations and regulatory audits |
Two things are worth pulling out of that table. First, administrator access to your mailbox or OneDrive is itself recorded — the audit log captures the administrator's name, the time, and what was opened, which is exactly what an auditor asks for. Second, you can see your own sign-in history without asking anyone: see How to Check Your Sign-In Activity in Microsoft 365.
What is not standard equipment: keystroke logging, silent screenshots, and webcam access are not built into Microsoft 365. Some employers deploy separate monitoring software that does those things, and in most jurisdictions they are required to tell you when they do. If nobody has told you, it is reasonable to assume it is not running — and reasonable to ask.
6. Possible, Routine, and Permitted Are Three Different Things
Nearly every anxious conversation about workplace monitoring collapses these three, so separate them.
- Technically possible is a long list. Most of section 2 through 5 sits here.
- Routinely done is a very short list: automated security alerts, licence and patch reporting, and blocked-site counts. Nobody on the help desk has the hours to read your mail, and nothing in their daily work would surface it if they wanted to.
- Permitted is narrower still. Reading an individual's mailbox or files normally needs a documented request from HR, Legal, or a security investigation, an approver who is not the requester, and a record of what was accessed. In much of Europe, works councils and data protection law add consultation requirements on top; several US states require written notice before electronic monitoring.
The useful mental model is a hotel: staff hold a master key to your room, they are permitted to use it for cleaning and emergencies, there is a record of every entry, and using it to read your diary would cost someone their job. The key exists. That is not the same as it being used.
7. Keep Personal Life Off the Work Device — and Read the Policy
None of this requires anxiety. It requires one habit and one document.
The habit: keep personal matters on personal equipment.
- Do personal email, banking, medical, and job hunting on your own device, over your own connection. This single rule removes almost every real risk.
- Keep personal files out of work OneDrive and work SharePoint. Move anything already there to personal storage now rather than during your notice period. See Understanding What to Do When You Leave or Change Jobs — IT Offboarding Checklist.
- Do not sign a personal browser profile in to the work computer, and do not save personal passwords in the work browser profile. If you already have, remove them from the browser's saved passwords list and change anything sensitive from a personal device.
- Use your phone on cellular data for personal calls and messages, rather than the office Wi-Fi.
The document: your acceptable use policy. Every employer that monitors anything has one, and you almost certainly accepted it at your first sign-in without reading it. Look in the HR section of the intranet, in your onboarding pack, or in the employee handbook. If you cannot find it, send HR this: "Please send me the acceptable use policy and any workplace monitoring notice that applies to my work computer." That request is routine, it is your right in most jurisdictions, and the answer tells you exactly where the line sits at your company rather than in general.
Troubleshooting
INFO
Nothing in this article is unique to Microsoft 365. Google Workspace, Slack, Zoom, and every other business platform have equivalent administrator access, retention, and audit features, because the same regulations require them. Changing tools does not change the answer.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| You deleted an email and want it permanently gone | Retention policy or legal hold preserves a copy | Deletion from your view is the limit of your control. Ask HR or Legal about the retention schedule that applies to your mailbox. |
| Personal photos and documents sit in your work OneDrive | Personal files on company storage | Copy them to personal storage and delete the work copies now. Accounts are closed on the last working day, often without warning. |
| You clicked a blocked website by accident | The web filter logged the request | Blocked requests are counted, not investigated. No action needed. |
| You want to know exactly what your employer monitors | The policy has never been read | Send HR: "Please send me the acceptable use policy and workplace monitoring notice for my device." |
| Personal passwords are saved in the work browser | A personal account was signed in to the work profile | Remove them from the browser's saved passwords list, then change those passwords from a personal device. |
| You suspect your mailbox has been opened by someone else | Delegated access or an investigation | Check your own sign-in and mailbox activity first, then ask HR: "Has non-owner access been granted to my mailbox, and under what process?" |
Related Articles
- Understanding the Incognito Mode Myth
- Understanding Company Portal, Device Management, and Your Privacy
- Understanding Microsoft Viva Insights: Can My Boss See My Activity?
- Understanding What Copilot Can See — Privacy and Data Access
- Understanding Windows Recall — What It Records and Your Privacy
- How to Secure Your Personal Phone for Work
- Understanding IT Policies: Why You Can't Download That App
- Understanding What to Do When You Leave or Change Jobs — IT Offboarding Checklist