Skip to content
HexaTransfer
Back to blog
Comparisons & Alternatives

OneDrive vs Encrypted File Transfer: Which Is Safer

Compare OneDrive file sharing security with dedicated encrypted file transfer services to determine the safest option for sensitive data.

OneDrive is safer than sending files over unencrypted email or FTP, but it's not end-to-end encrypted. Microsoft holds the keys, which means they can decrypt your files for content scanning, eDiscovery, and lawful access requests under the US CLOUD Act and the Stored Communications Act. Dedicated encrypted file transfer services like HexaTransfer, Tresorit Send, and Proton Drive Send encrypt files client-side with AES-256-GCM so the provider only stores ciphertext. For non-sensitive collaboration, OneDrive's convenience wins. For regulated data under HIPAA, GDPR Article 32, or PCI DSS 4.0, an E2EE transfer service is materially safer.

How OneDrive Actually Encrypts

OneDrive encrypts files at rest using per-file AES-256 keys, which are themselves encrypted by a content encryption key stored in Microsoft's Key Store, which is protected by a master key in Azure Key Vault. It's a well-engineered chain, and in transit everything uses TLS 1.3 with modern cipher suites. Microsoft's documentation is unusually transparent about the architecture.

None of this is end-to-end encrypted. Microsoft holds the keys at every layer. SharePoint (which underlies OneDrive for Business) performs content scanning, DLP policy evaluation, and malware detection against plaintext. These features are valuable — they're also incompatible with E2EE by design.

Microsoft's Double Key Encryption (DKE)

Microsoft 365 E5 customers can enable Double Key Encryption, which adds a customer-held key on top of Microsoft's. To decrypt a DKE-protected file, both Microsoft's key and your on-premises key (served from a customer-run DKE service) must combine. Microsoft alone can't decrypt; they need your key service to respond.

DKE is genuine E2EE for the subset of files you specifically protect. The setup cost is real: E5 licensing ($57/user/month), hosting the DKE service, managing key rotation, training users on the Protect button in Office. For large organizations handling classified contracts, it's proportional. For most small businesses, it's overkill.

What Dedicated Encrypted Transfer Services Do Differently

HexaTransfer, Tresorit Send, and Proton Drive Send all implement the same architectural pattern: encryption happens in the sender's browser before upload. The symmetric key (AES-256-GCM) is generated client-side. The server stores only ciphertext. The key travels to the recipient separately — in a URL fragment, a password, or a pre-exchanged public key.

No Microsoft key, no Azure Key Vault, no need for the provider to participate in decryption. The threat model shifts: instead of trusting the provider, you trust only the endpoints and the key-transport channel. For many regulated scenarios, that's exactly the posture auditors want to see.

Comparison: OneDrive vs Dedicated E2EE Transfer

| Property | OneDrive for Business | OneDrive + DKE | HexaTransfer | |---|---|---|---| | Encryption at rest | AES-256 (MS-managed) | AES-256 (MS + customer) | AES-256-GCM (client-side) | | Provider sees plaintext | Yes | No | No | | Setup complexity | None | High (E5 + DKE service) | None | | Cost per user | $5–22/month | ~$57+/month | Free | | Max file size | 250 GB | 250 GB | 10 GB | | Retention | Persistent | Persistent | 7 days | | Admin audit log | Yes | Yes | Minimal | | BAA available | Yes | Yes | Provider-dependent |

Scenario-by-Scenario Safety

For a staff shared drive of onboarding documents, OneDrive is fine — the content isn't sensitive and collaboration matters. For a marketing asset library, OneDrive is fine. For a contractor's SOW .pdf being emailed out via OneDrive link, OneDrive is probably fine, though a password-protected link is better than an anonymous one.

For a breach-response forensic report being sent to outside counsel, an E2EE transfer service is materially safer. For patient imaging (DICOM files) sent between clinics, an E2EE service with a HIPAA BAA is the defensible choice. For M&A due-diligence documents, an E2EE service plus compartmented access is standard practice. For attorney work-product sent to opposing counsel, E2EE protects against wire-level intercept and provider-level compromise simultaneously.

The CLOUD Act Wrinkle

The US Clarifying Lawful Overseas Use of Data Act (2018) lets US law enforcement compel disclosure of data held by US providers regardless of where it's stored physically. OneDrive data hosted in Ireland is still subject to US process. This matters for non-US organizations: a German company storing EU customer data on OneDrive is in a cross-jurisdictional conflict when a US warrant arrives.

E2EE transfer services where the provider cannot decrypt sidestep this directly. A CLOUD Act warrant against a provider that stores only ciphertext produces exactly ciphertext. Some services (Proton, Tresorit) are headquartered outside US jurisdiction entirely, adding another layer of protection.

Practical Hybrid Strategy

Most organizations running Microsoft 365 shouldn't abandon OneDrive — it's too tightly integrated with Teams, Outlook, and Windows. Instead, add an E2EE transfer service for sensitive external sends. The workflow: store the working file in OneDrive for editing, export a final version, and send via HexaTransfer or Tresorit Send to the external recipient. The OneDrive copy stays with you under Microsoft's key management; the external delivery is E2EE.

This keeps Microsoft's DLP, eDiscovery, and retention tooling intact for internal compliance while closing the weakest link — the external send where provider plaintext access matters most.

What Your Risk Assessment Should Ask

Three questions reveal whether OneDrive alone is safe enough. First, would a Microsoft employee reading this file cause regulatory or competitive damage? If yes, move to DKE or an E2EE service. Second, would a US government subpoena to Microsoft for this file create a legal problem under a non-US law (GDPR, PIPL, LGPD)? If yes, E2EE is safer. Third, is this a one-time send or an ongoing collaboration? If one-time, an E2EE transfer service is operationally simpler than configuring DKE.

For the one-time E2EE send case, try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file