Microsoft Office 365 has ability to ‘spy’ on workers (2022)

Businesses can use risk management tools in Microsoft Office to covertly monitor the activities of employees on work-issued computers.

The software company provides tools in its Office 365 suite that can be used by employers to read staff emails and monitor how long they spend on calls and how many meetings they attend.

The surveillance capabilities of Microsoft’s Office suite, which is widely used by businesses across the world, were disclosed in a dissertation by a researcher at University College London (UCL).

The research shows that companies continue to exploit capabilities built into Office 365 to monitor staff computers some 18 months after Microsoft took steps to protect employees’ privacy.

The disclosure has led to calls for Microsoft to change its software to alert staff when companies use its Office 365 productivity tools to monitor identified employees.

Eliot Bendinelli, senior technologist at campaign group Privacy International, which participated in the research, said Microsoft should be more transparent about the data it enables companies to collect.

“The ability for an employer or an IT administrator to read all communications and documents, and to access data about employees’ online activities without their knowledge, is one of the most problematic features of Office 365,” he told Computer Weekly.

Microsoft introduced measures to protect the privacy of employees in Office 365 in 2020 following criticism that its Productivity Score tool allowed managers monitor individual employees.

“The ability for an employer to read all communications and documents, and to access data about employees’ online activities without their knowledge, is one of the most problematic features of Office 365”

The company replaced its reports with aggregated data measuring how much employees were sending email, collaborating on shared documents and taking part in group chats, in a way that was not traceable to individual users.

But research by UCL computer science graduate Demetris Demetriades and Privacy international shows that employers are still able to use functions in Office 365 to monitor individual employees.

(Video) SPY ON EMPLOYEES EMAILS and VOICE Communication with OFFICE 365

Demetriades found employers can use the governance and risk management tools in Office 365 to look at the content of emails or messages sent by specific employees and identify the activities that individual users have carried out using their work computer.

Microsoft’s “content search” and “audit” tools can be used by employers to build up a detailed picture of employees’ activities, he told Computer Weekly.

“Whatever interaction is performed through business email, the audit and content search features identify it and log it. For example, they log the time of the email, the recipient and the content of the email. If the email contains attachments or a picture, the employer can see that too,” he said.

Privacy International argues in an article about Demetriades’ research that these tools can be used to build up a detailed profile of an employee.

“Combining these two all-encompassing features, employers are able to draw a rather intimate picture of every employee, down to the finest of details. This includes not only a list of most of the actions they take, but also the possibility to plainly access all the content being exchanged within the organisation and external communications through email,” it said.

Monitoring Team players

IT administrators can also use the administration centre in Microsoft Teams video conference, messaging and collaboration software to assess how long employees spend on calls, how many messages they exchange and how many one-to-one meetings they take part in.

The software records which devices employees use to attend each meeting or send each message, potentially allowing employers to make inferences about employees.

For example, managers might make the assumption that an employee who joins an early morning meeting from their phone, rather than their laptop, might still be in bed.

Microsoft provides companies with aggregated data showing how employees across the organisation, or individual groups, are using Office 365 applications. It also provides them with a productivity score that shows how well employees are using Office 365 capabilities compared with similar companies.

For smaller organisations, this data can still be used to make inferences about the performance of individual employees, Demetriades and Privacy International found.

The audit and content search tools offered by Microsoft have legitimate uses, such as allowing employers to identify breaches of employment contracts, breaches of company policies on harassment and the disclosure of trade secrets.

(Video) Tracking Employees with Microsoft 365

But Demetriades and Privacy International argue there are no safeguards to protect employees from auditing tools being misused and Office 365 users are given no warning if companies choose to enable those tools.

“This lack of transparency and limitations on the employee side means they can potentially be misused and turned into a surveillance machine without employees’ full knowledge,” they claim.

‘Pseudonymised by default’

Microsoft did not contradict the UCL research, but said in a statement to Computer Weekly that it uses masked or “psuedonymised” information about users of Office 365 “by default”.

“We do not believe in using technology to spy on individual employees. Most of the Microsoft 365 analytics tools that provide insights into adoption and usage do so at the aggregate level – across groups or entire organisations”

Revealing identifiable user information is treated as a logged event in the Microsoft 365 compliance centre audit log, the company added.

“We do not believe in using technology to spy on individual employees. Data-driven insights have long been a critical part of how IT professionals deploy and manage solutions, provide services, meet regulatory requirements and fix problems across their organisations,” a spokesperson said.

“Most of the Microsoft 365 analytics tools that provide insights into adoption and usage do so at the aggregate level – across groups or entire organisations. These tools are an important part of helping organisations run effectively and get the most out of their investment,” the spokesperson added.

Microsoft should alert employees to monitoring

Although Microsoft mentions in its privacy policy that Office 365 can be used by organisations to “access and process your data”, including “the contents of your communications and files”, it is unlikely to be noticed by employees who may have to consent to the software their company is using.

Microsoft does not limit how employers can use its “audit” and “content search” tools, which means they could potentially misuse them to spy on employees without consent.

If employers do not disclose which Office 365 capabilities are turned on, employees have no way of knowing “whether their every action with Office 365 is being monitored or even if their communications are being read by someone”, the privacy group argued.

Microsoft Office 365 has ability to ‘spy’ on workers (1)

Demetriades said Microsoft could do more to prevent employees being spied on by their employer, such as introducing a dedicated dashboard accessible to all employees that lists which productivity apps have been enabled or disabled and what data the organisation is collecting and under what circumstances.

(Video) Microsoft's Workplace Surveillance WHAT YOU NEED TO KNOW!

Microsoft should also notify Office 365users when companies turn the “audit” and “content search” features on, and if administrators disable the option to conceal usernames in Office 365 to generate reports about named individuals, he added.

“I am not saying these features should be removed completely, because they are good for productivity, but they should be used to provide aggregate information,” said Demetriades.

There are other ways to see whether individual employees are being productive rather than using these metrics, he added.

Employers have legal responsibilities

Under UK data protection law, employers are responsible for ensuring they comply with the law when using software to monitor employees.

Companies need to ensure that monitoring employees at work is proportionate, and if it is proportionate, whether they can justify collecting data on employees without informing them first, said IT lawyer Dai Davies.

“The real problem is that there is no black and white answer. What is proportionate in one situation is not proportionate in another,” he said.

For example, it is probably proportionate and lawful for a retailer to install a hidden camera where there are grounds to suspect a staff member of pilfering from a till. However, it would not be proportionate for a company to record the key strokes made by every secretary employed by the organisation to identify the least productive typists.

“Monitoring everyone is much more problematic than monitoring a few people. One of the problems with Microsoft Office 365 is that it allows monitoring of every employee and is therefore harder to justify,” said Davis.

He said Microsoft had failed to acknowledge that employers could combine data gathered from Office 365 with other data they hol on their staff.

Legitimate reasons for monitoring employees

David Wilson, CEO of Fosway Group, an analyst specialising in the human resources industry, said there were legitimate reasons why companies might want to monitor employees.

These include monitoring workplace apps to identify patterns of use or monitoring email to identify intellectual property theft or workplace harassment.

(Video) How Employers Could Be Spying On You While Working From Home

“It is hard to argue that a company should not be allowed to access staff emails or browsing history if there are business-critical or legal reasons. The issue is more one of governance and ensuring that monitoring capabilities are not abused”

“It is hard to argue that a company should not be allowed to access staff emails or browsing history if there are business-critical or legal reasons. The issue is more one of governance and ensuring that monitoring capabilities are not abused,” he said.

For example, pharmaceutical companies ask employees for consent to use software to automatically screen their emails and social media to see whether rival companies are mentioned to ensure that employees do not accidently leak confidential information to a competitor.

The same software could be used to identify employers who have applied for jobs with competing companies.

Office 365 simulation

Demetriades used a trial version of Office 365 to simulate a company network made up of two users and a systems administrator as part of his research project for a masters in information security at UCL.

“I set up an admin account, which represented the employer, and I added two user accounts, which represented employees,” he told Computer Weekly. “I used my laptop and my phone, and I logged each user in on one device, and I tried to interact with simple messages and set up meetings to collect data. The platform tracked the data and it started to generate the graphs and the metrics.”

Demetriades, a software engineer, said it would be “very easy” for an employer to select and read emails sent by a particular employee.

Microsoft boosted Office 365 privacy in 2020

Microsoft announced plans to remove user names from its Productivity Score tool in a blog post in December 2020, in response to criticism that the feature could be misused by employers.

“No one in the organisation will be able to use Productivity Score to access data about how and individual user is using apps and services in Microsoft 365,” it said in the post.

The company also changed the interface of its software to make it clear the purpose of Productivity Score was to monitor the adoption of technology within the organisation rather than to monitor individual employees.

But Demetriades’s research shows that Office 365 can still be used by employers to monitor that activities of their staff.

(Video) The New Microsoft 365 - Get Up To Speed (Again) | Video Meetup

Microsoft said in its statement that there were scenarios where IT professionals need access to “user-level information” to identify and fix problems or to track software licences.

“Access to these reports is restricted to only a few IT-focused roles. Moreover, Microsoft generally takes the step of concealing user, group and site information by default,” a spokesperson said.

FAQs

Can Office 365 spy on employees? ›

Demetriades found employers can use the governance and risk management tools in Office 365 to look at the content of emails or messages sent by specific employees and identify the activities that individual users have carried out using their work computer.

Can my work see what I do on Microsoft Office? ›

The answer is no, if they are created locally rather than Word or Excel online, the admins cannot access them.

Can your employer spy on you via Microsoft Teams? ›

The short answer is that Teams meetings can be monitored, recorded, transcripts recorded, documents and chat recorded by internal people such as those included in calls, meetings, chat, or by an employer.

Can Microsoft Office be monitored? ›

Use System Center to Monitor Microsoft 365

If you're using Microsoft System Center, you can download the Microsoft System Center Operations Manager Management Pack for Microsoft 365 to begin monitoring Microsoft 365 today. For more detailed guidance, please see the management pack operations guide.

Does Microsoft track employee activity? ›

Yes, Microsoft Teams (MS Teams) can help employers monitor employees. As a manager, you can track almost everything your employee does within Teams. This includes text conversations, recorded calls, Zoom meetings, and more.

Does Microsoft Teams track your activity? ›

The Teams user activity report can be viewed for trends over the last 7 days, 30 or 90 days. Each report has a date for when this report was generated. The reports usually reflect a 24-hour latency from time of activity.

How can I tell if my computer is being monitored at work 2022? ›

Open task manager by right-clicking on the taskbar and choosing Task Manager. If there's a suspicious process, that's the monitoring app. Question: Can my company see what I do on my computer? Answer: Your company can see your device activities and track them if they provide you with that computer.

Can my boss see what I'm doing on my computer? ›

There are numerous ways employers can track workers' productivity. If you are using a work laptop or are connected to your company's virtual private network, your employer has the ability to monitor nearly everything you do.

Can my boss watch me on camera all day? ›

Conclusion: Your Boss Can Legally Monitor Any Activity on a Work Computer or A Work Network. As you now know, your boss can monitor almost anything you do during the day - whether you're working remotely or have returned to the office.

Can Microsoft Teams see my screen? ›

The other participants in the chat will receive a notification asking them to accept your screen share. Once they do, they'll be able to see your screen and continue the chat. When you're done sharing, go to your meeting controls and select Stop sharing.

Can your employer listen to you through your laptop? ›

Can My Employer Hear Me Through My PC? In general, yes. Your boss can hear you and your conversations with others if your device has a built-in microphone and the office has installed any tracking software. Usually, the office-provided device you use for working comes installed with the tracking software.

Can Microsoft Teams detect cheating? ›

Microsoft Teams cannot detect cheating. The app cannot detect what users are doing outside of the Teams window. If you're a teacher and you want to prevent students from cheating during exams, you need to use dedicated anti-cheating software.

Can my boss listen to my conversations? ›

Generally, employers are not allowed to listen to or record conversations of their employees without the consent of the parties involved. The Electronic Communications Privacy Act (ECPA) allows employers to listen in on business calls, but are not allowed to record or listen to private conversations.

Can my boss see my Teams messages? ›

If you are on the business plan of your organization, then anything you do on Microsoft Teams or any other MS Office apps will be visible to your employer. From the moment you log in, your employer can keep track of your calls, meetings, chats, etc.

Can an employee spy on another employee? ›

In general, employees have no legal expectation of privacy in their workplace activities, particularly in their use of company computers. Employers are entitled to utilize reasonable methods such as video surveillance or computer monitoring programs to monitor employee activity on company time.

How do Microsoft Teams monitor employees? ›

Monitor MS Teams to track employee activities
  1. Navigate to the Reports tab.
  2. Go to Teams Reports in the left pane.
  3. Select Teams Usage Reports > Daily Teams User Count by Activity or any other report as per your requirement.
  4. Enter the Tenant,Domain,and Period of search.
  5. Click Generate Now.

How does Microsoft Teams track your work? ›

Microsoft Teams tracks three types of usage data, i.e., Census, Usage, and Error Reporting Data. Census data is nothing more than standard information about your device, operating system, and use language. It also generates a specific user ID that is double protected to avoid unnecessary binding.

Can my employer monitor my personal phone? ›

Employers can only monitor your personal data if you sign a written contract permitting them to monitor your personal devices. If you are using a device owned by the employer, he can track the activity of your device and even can go through your personal emails and social accounts.

What can Teams admin see? ›

YOUR bosses may or may not have actual access, but Teams retains a log of everything it does for whoever the "admin" of your group is. Anything you say or do through it can be looked at later. It would be a poor decision to have conversations through Teams that you wouldn't want the rest of the company to know about.

How can I tell if I am being monitored at work? ›

#1 Check Task Manager to if there's a monitoring program running. Most companies using third-party monitoring software which enables the executive to see what you do with the company's computer. Assuming your work computer using Windows, you might able to check from Task Manager whether the computer is been monitoring.

Is my computer being monitored? ›

How to Check If Your Computer Is Being Monitored
  • Look for Suspicious Processes. Suspicious processes may indicate that your computer is being monitored. ...
  • Run Antivirus Software. Antivirus software can reveal whether or not your computer is being monitored. ...
  • Evaluate Ports. Another tip is to evaluate your network's ports.
16 Feb 2021

Can my employer see what websites I visit on home Wi-Fi? ›

No. They cannot see what you are doing. Did you install any piece of software provided by your employer onto your own device or did you have to make any specific settings on your own device in order to use your employer's wifi?

Can your employer spy on you at home? ›

Is it legal to monitor remote employees in California? In California, employers can face criminal penalties for eavesdropping or recording their employees' private communications via telephone or email unless all parties to the communication consent to the monitoring (California Penal Code § 631).

What should you not do on a work computer? ›

10 Things You Should Never Do on a Work Computer
  • DON'T: Save personal passwords. ...
  • DON'T: Whine, overshare, gossip or make off-color jokes on messaging software. ...
  • DON'T: Access free public Wi-Fi. ...
  • DON'T: Shop. ...
  • DON'T: Work on your side hustle. ...
  • DON'T: Look for a new job. ...
  • DON'T: Store your personal photos.
3 Jul 2021

How can you detect a hidden camera? ›

7 Ways to Spot Hidden Cameras
  1. Look for Odd Objects. It's a good practice to thoroughly scan your surroundings whenever you enter a new room. ...
  2. Use a Flashlight. ...
  3. Use Your Smartphone Camera. ...
  4. Scan the Wi-Fi Network. ...
  5. Use a Phone Call to Detect Interference. ...
  6. Use a Hidden Camera Detector App. ...
  7. Use a Specialized RF Detector.
13 Jul 2022

Can my employer spy on my computer? ›

This means the IT department or company managers also have the same sort of computer access they have at a physical office. For most people, that means monitoring your internet browsing activity, but typically it also means they can see any files you've stored or documents you're working on.

Why is my boss checking up on me? ›

They check in with you

If your manager checks on you from time to time, but not excessively, it's likely they enjoy interacting with you and want to make sure you're okay. They are probably checking in to make it clear they want to support you as you work.

Can your employer listen to you through your laptop? ›

Can My Employer Hear Me Through My PC? In general, yes. Your boss can hear you and your conversations with others if your device has a built-in microphone and the office has installed any tracking software. Usually, the office-provided device you use for working comes installed with the tracking software.

Can employers see your OneDrive? ›

OneDrive for Business is a secure cloud-based solution for convenient telecommuting, remote access and private file sharing. Indeed, files stored on OneDrive are private by default: Users control access to the files they upload, so they can be seen by other employees only if they have been shared by the OneDrive owner.

Can my company see my Word documents? ›

The answer is “yes” — and you might be surprised by what your supervisors can see. Your work computer is not as private as you think it is, and with the help of technology like firewalls and monitoring software, your boss can see every file you access, every website you browse and even every word you type.

Does Outlook track browsing history? ›

So based on this, Outlook does not tracks your activity, since the option to track is not available. Beware of Scammers posting fake Support Numbers here.

Can my boss watch me on camera all day? ›

Conclusion: Your Boss Can Legally Monitor Any Activity on a Work Computer or A Work Network. As you now know, your boss can monitor almost anything you do during the day - whether you're working remotely or have returned to the office.

How can I tell if my computer is being monitored at work 2022? ›

Open task manager by right-clicking on the taskbar and choosing Task Manager. If there's a suspicious process, that's the monitoring app. Question: Can my company see what I do on my computer? Answer: Your company can see your device activities and track them if they provide you with that computer.

Should you cover the camera on your laptop? ›

Cybercriminals can access these cameras, and because of their positions — facing your living room, kitchen, or office — they can expose your privacy and sensitive conversations. That's why it's a good idea to cover up your webcam or take other steps to improve your internet security.

Can Office 365 admin see my files? ›

To answer the question “Can IT personnel/admin see my OneDrive files?” the answer is yes, they can view your files and folders with or without your permission.

Can my employer monitor my personal phone? ›

Employers can only monitor your personal data if you sign a written contract permitting them to monitor your personal devices. If you are using a device owned by the employer, he can track the activity of your device and even can go through your personal emails and social accounts.

Can my coworkers see my OneDrive files? ›

By default, only YOU can see OneDrive files

So, nothing to worry about confidentiality and security. If you share a OneDrive file with someone, then obviously those people have access. You can always remove the rights at any point of time by going to OneDrive – select file – Sharing.

Is my work laptop being monitored? ›

Right-click on the Taskbar and select Task Manager. On the Process tab, find a program that potentially monitoring the computer. You might want to check out a top monitoring software to help you determine the name. If you found one exact same name, it means you are being monitored.

Can my employer see what websites I visit on home WIFI? ›

No. They cannot see what you are doing. Did you install any piece of software provided by your employer onto your own device or did you have to make any specific settings on your own device in order to use your employer's wifi?

Can Microsoft see your documents? ›

If you have installed Office 365 desktop application and if you save your files on your local drive, no one else will have the access unless you decide to share them with others using OneDrive for business or SharePoint online.

How do employers track you online? ›

But companies pull data not only via your web browser, but through smartphones and other devices as well. As companies collect data, they often gather that data into user profiles that can then be used to track people across devices. Meanwhile, third-party ad networks also track you across different websites.

Can my employer see what apps I use on my phone? ›

Employers can see your internet activity on your phone. Especially when it is a company phone, and you are connected to your company's network. A company phone runs on data and voice time that the company pays for so they may want to monitor how it is used.

What can my employer see on Microsoft teams? ›

If you are on the business plan of your organization, then anything you do on Microsoft Teams or any other MS Office apps will be visible to your employer. From the moment you log in, your employer can keep track of your calls, meetings, chats, etc.

Videos

1. Is Your Boss Monitoring Your Work? - BBC Click
(BBC Click)
2. (Microsoft 365) How Your Organization May Read Your Work E-mail
(The TWS Channel)
3. Power Automate 101 | Track working hours
(Office 365 Knowledge)
4. What your boss can track about you with Microsoft Teams
(Kevin Stratvert)
5. How employers monitor employees working remotely
(FOX 2 St. Louis)
6. What Your Boss Can TRACK About YOU with Microsoft Teams
(Leila Gharani)

Top Articles

Latest Posts

Article information

Author: Dean Jakubowski Ret

Last Updated: 12/19/2022

Views: 5539

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Dean Jakubowski Ret

Birthday: 1996-05-10

Address: Apt. 425 4346 Santiago Islands, Shariside, AK 38830-1874

Phone: +96313309894162

Job: Legacy Sales Designer

Hobby: Baseball, Wood carving, Candle making, Jigsaw puzzles, Lacemaking, Parkour, Drawing

Introduction: My name is Dean Jakubowski Ret, I am a enthusiastic, friendly, homely, handsome, zealous, brainy, elegant person who loves writing and wants to share my knowledge and understanding with you.