A previously-announced capability of OneDrive has been widely rolling out – the Personal Vault. This is a special area of your OneDrive Personal storage which is invisible until you choose to unlock it, using a second strong factor of authentication (such as 2FA and the Microsoft Authenticator mobile app). On a mobile device, you can use a PIN, fingerprint or facial recognition to provide the additional identity verification.
When you unlock the Personal Vault from the OneDrive app on your PC (eg. right-click on OneDrive’s white cloud icon in your system tray), it appears as a special folder under the root of your personal OneDrive folder list, on PCs where your OneDrive content is synchronised.
Browsing in your OneDrive data folder, you may need to enable Hidden Items in the View tab to even see it.
You can treat it like any other folder, adding files and other folders that are particularly sensitive – scans of important but infrequently-accessed documents like passports, driving licenses and so on.
Why infrequently accessed, you may ask?
When the PV is visible, it will re-lock after 20 minutes of inactivity (or can be locked manually) and would need another 2-factor authentication method to unlock it again (text message, phone-app approval etc). On the PC, when the PV is locked, the “Personal Vault” folder (and therefore everything under it) is completely hidden and therefore any files within it do not exist as far as Windows is concerned.
In fact, the PV isn’t just a hidden folder – it’s treated by Windows as another physical volume that is mounted on the PC for the duration of it being unlocked; a Junction is then created so it can be accessed as if it’s part of your OneDrive data folder. When the PV is locked again, the volume is dismounted and the junction disappears, so there is no way to access the data using the normal file system.
If you had a file in your now-locked PV that you tried to access from the most-recently-used files list in either Windows itself or within an app, you’ll get a jarring “file does not exist” type error rather than a prompt to unlock the PV and the file within.
Maybe apps will in time come to know that a file is in PV, and prompt the user to unlock before opening?
Then again, security through obscurity (the most sophisticated form of protection, right?) might be a good thing here; when the PV is locked, there is no such folder therefore no apps can get access to it without the user taking specific and separate action to unlock it first. Not being seen is indeed a useful tactic.
Personal Vault can be accessed from the PCs or mobile devices through the OneDrive app, or in a browser – at onedrive.com. No Mac support is planned.
Unlike in the PC scenario, the PV folder is always shown and indicates if it’s open or locked based on the icon.
The Web UI offers other help and advice about how to use the Personal Vault effectively.
OneDrive on PC – Setup error 0x8031002c
Enabling Personal Vault for the first time might throw an error if your PC is corporately managed with a BitLocker policy.
To work around this and get up and running, try: