SharePointSecurityHub

Is SharePoint Encrypted? How to Secure Files, Links and Synced Copies

This guide explains those layers separately. It also places Cloud Secure in the correct category: a Windows utility that restricts ordinary local access to supported cloud-sync folders. It is not SharePoint encryption, it does not encrypt document contents, and it does not make Microsoft 365 a zero-knowledge service.

SharePoint encryption and secure file access across Microsoft 365

What SharePoint Encryption Covers

SharePoint Online uses more than one form of service protection. Data traveling between a client and Microsoft is carried over encrypted connections. Stored content is protected at the disk layer and again through file-level service encryption.

In transit

Protection while data moves

TLS helps prevent someone on the network path from reading files, page requests or account traffic as they travel between the device and Microsoft 365.

At rest

Protection inside Microsoft storage

Microsoft applies volume encryption and file-level service encryption to content stored in SharePoint and OneDrive. This mainly protects the storage infrastructure and separates encrypted content from the keys needed to reconstruct it.

Microsoft 365 security controls protecting SharePoint and OneDrive data

Encryption is not the same as authorization

When an approved user opens a document, SharePoint must deliver readable content to that user. As a result, service encryption cannot correct an overly broad permission, an exposed sharing link, a stolen account session or a downloaded copy left on an unlocked computer.

Useful security model: service encryption protects the platform, permissions decide who may open content, information protection can keep restrictions attached to a document, and endpoint controls protect copies available on a device.
Quick Exposure Check

This is a simple prioritization tool, not a compliance assessment.

1. How is sensitive content normally shared?
2. Are local downloads and sync copies controlled?

Built-In SharePoint Protection Methods

Start with Microsoft 365 controls because they govern access to the source content. A desktop folder lock cannot repair unsafe permissions in the cloud.

1. Choose the narrowest useful sharing link

Difficulty:
Easy

For confidential material, prefer a link limited to specific people. Organization-wide links are easier to forward internally, while Anyone links can be passed to unauthenticated recipients and are harder to audit at the person level.

  1. Select the file or folder and open the sharing settings.
  2. Choose Specific people when the recipient list is known.
  3. Grant view access unless editing is required.
  4. Set an expiry date where your tenant supports it.
  5. Remove the link when the collaboration period ends.
Password options for public links depend on tenant policy and the sharing experience available to the account. Do not design a security process around that option until it has been tested in the actual Microsoft 365 tenant.
Step-by-step security workflow for reviewing SharePoint sharing links

2. Review direct permissions and guest access

Difficulty:
Routine administration

Sharing links are only one path to a file. Site membership, Microsoft 365 groups, inherited library permissions and external guest accounts can also provide access. Review all of them before assuming a document is private.

Secure folder synchronization between a Windows device and cloud storage

3. Apply sensitivity labels when restrictions must travel with the file

Difficulty:
Administrative planning required

Microsoft Purview sensitivity labels can apply encryption and usage rights to supported files. When correctly configured, those controls can remain active after a file is downloaded. This approach is more suitable than a local folder lock when the goal is to control who may open, print, copy or edit the document itself.

  • Good fit: regulated documents, internal classifications and consistent policy across Microsoft 365.
  • Plan for: licensing, label publishing, application support, external-user access and co-authoring behavior.
  • Test first: search, eDiscovery, DLP and browser editing can behave differently depending on how encryption is applied.
Sensitive personal and business data requiring controlled document access

Four Different Protection Layers

Products in this category are often compared as though they solve the same problem. They do not. The table below separates the main security outcomes.

Control Main purpose Protects after download? Changes file contents?
SharePoint service encryption Protect Microsoft-hosted storage and network transport No, not by itself No user-managed file encryption
Permissions and sharing policies Decide which identities may reach cloud content Usually no No
Purview sensitivity label with encryption Carry identity-based usage rules with supported documents Yes, when supported and configured Applies document protection
Independent client-side file encryption Upload ciphertext that the cloud provider cannot read without the user-held key Yes Yes
Cloud Secure desktop lock Restrict normal local access to supported sync folders on one Windows system Only while the folder remains under that local control No
Private files synchronizing securely between local storage and cloud services
Correction to the earlier page: Cloud Secure should not be described as client-side encryption, end-to-end encryption or zero-knowledge storage. Its documented role is local folder access control for supported Windows cloud clients.

Where Cloud Secure Fits

Cloud Secure is most relevant when a Windows computer contains locally synchronized Dropbox, Google Drive, OneDrive or Box folders and more than one person may use or reach that device.

☁️
Supported sync folder on Windows
→ 🔐 →
🖥️
Password-gated local access
🔄
Background sync can continue

Cloud Secure is made by NewSoftwares.net. The product page and store should be checked before installation or purchase because compatibility, pricing and release status can change.

Cloud Secure Features in Practical Terms

The useful differentiator is convenience at the endpoint. The application brings several supported cloud clients into one password-protected control panel rather than requiring a separate local lock for each folder.

Unified desktop interface for controlling multiple cloud storage folders
Background cloud synchronization continuing while local folder access is restricted
The application uses one primary credential to open its control panel and reach protected cloud folders. This reduces local password clutter, but it also makes that credential especially important.
After installation, Cloud Secure is designed to locate supported cloud applications already configured on the PC and display them in one place.
A user can protect one supported service or apply the lock across every detected service from the same interface, then reverse the action when ordinary desktop access is needed.
When protection is active, the normal desktop route to the folder is restricted. The user opens the application and uses its viewing control to reach the files.
The vendor says the cloud client can continue its background upload and download work while the local folder remains protected through Cloud Secure.

Typical Setup Flow

The desktop software is intended to sit on top of cloud clients already installed on the Windows computer.

User unlocking protected cloud data through a password-controlled desktop interface
Prepare the cloud clientsInstall and sign in to the Dropbox, Google Drive, OneDrive or Box desktop application you plan to protect.
Install Cloud SecureRun the Windows installer using an account allowed to install the required local components.
Create the primary passwordUse a long, unique credential and record the recovery plan before protecting important folders.
Confirm detected servicesCheck that each intended cloud client appears in the Cloud Secure panel.
Turn protection onApply the lock to one service or to all supported services shown on the machine.
Test access and syncVerify that the normal folder path is restricted, the in-app viewing method works and the provider continues synchronizing.

Compatibility, Pricing and Limitations

This section is intentionally specific so the product is not presented as broader than its documented capabilities.

Windows desktop compatibility for local cloud folder protection software
Desktop services Dropbox, Google Drive, Microsoft OneDrive and Box
SharePoint support Not documented as a direct integration. A SharePoint library may be synchronized through OneDrive, but the vendor material does not promise SharePoint-specific recognition or protection. Test the exact folder layout before relying on it.
Desktop operating system Windows-focused. The vendor lists Windows 11, 10, 8 and 7, plus Windows Server 2008, 2012, 2016 and 2019 in 32-bit or 64-bit environments.
File systems Vendor documentation names FAT32, exFAT and NTFS.
macOS and Linux No equivalent desktop support is documented.
Mobile Separate iOS and Android apps are promoted, but their vault-style feature set is not the same as the Windows cloud-folder locking workflow described on this page.
License model A limited evaluation is available. The full desktop edition is sold as a one-time license.
Price checked US$34.95 one time on July 18, 2026. Confirm the amount and terms at checkout.
Latest listed desktop release Version 1.1.3, dated April 22, 2022, is the newest entry shown in the official version history reviewed for this update.

Good fit

Not the right fit by itself

Master password caution: vendor instructions describe a serial-key recovery route for registered users when the recovery feature is enabled. Treat recovery as something to configure and test in advance, not as a guaranteed reset after a forgotten password.

SharePoint and Endpoint Audit Checklist

A secure setup combines cloud review with device review. Run this checklist after staff changes, major sharing projects and endpoint migrations.

Shared Windows computer secured against unauthorized access to synchronized files
Security Review
Find Anyone links, confirm business need and remove or expire those no longer required.
Inspect site membership, Microsoft 365 groups, direct permissions and inherited access.
Remove former vendors, contractors and other external guests who no longer need access.
Identify sensitive libraries that can be synchronized or downloaded to unmanaged devices.
Confirm Windows sign-in, screen lock, disk encryption and local sync-folder controls on managed PCs.
For Cloud Secure deployments, test each supported provider after Windows or sync-client updates.

Troubleshooting SharePoint and Cloud Secure Locks

A SharePoint editing lock and a Cloud Secure folder lock are unrelated. Diagnose the layer that is actually blocking access.

SharePoint file opens read-only or reports another editor

  1. Ask every active editor to close the desktop and browser copy of the document.
  2. Open the file in the browser to determine whether the problem is local to the Office app or sync client.
  3. Check whether the library requires checkout, mandatory metadata or approval before editing.
  4. Review the OneDrive sync client for pending uploads, sign-in errors or a conflicting local copy.
  5. When a formal checkout is abandoned, a site owner can review the library and discard or take over the checkout where policy allows.

Cloud Secure does not show a cloud service

  1. Install the provider's Windows desktop client and complete its sign-in first.
  2. Confirm that the service uses its expected primary local folder rather than an unusual custom layout.
  3. Restart Cloud Secure after the provider has created its folder and completed an initial sync.
  4. Re-test after cloud-client updates because detection depends on local integration.

A protected folder is still reachable

Check whether you are opening a second copy, a browser session, a shared network path or a different sync root. Cloud Secure is designed for the local folder it recognizes; it cannot remove access granted elsewhere.

The master password is forgotten

Do not assume uninstalling the application is a safe recovery method. Use the registered recovery process only if it was enabled and the purchase serial is available. For critical data, validate recovery before deployment and keep a separate administrative copy of the plan.

Folder security troubleshooting for local and cloud file access controls

Frequently Asked Questions

Is SharePoint Online encrypted?
Yes. Microsoft encrypts SharePoint data in storage and protects client connections with TLS. Those measures do not eliminate permission errors, risky links, stolen sessions or exposed local copies.
Does Cloud Secure encrypt SharePoint files?
No. It restricts ordinary access to supported local cloud folders on Windows. It does not encrypt file contents and it is not a SharePoint security add-on.
Can Cloud Secure protect a SharePoint library synced with OneDrive?
Possibly, but this is not promised in the vendor's documented support list. Because SharePoint libraries can appear inside the OneDrive sync structure, the exact result depends on how the folder is presented locally. Test the intended library before deployment.
Which cloud clients are supported on Windows?
The documented desktop list is Dropbox, Google Drive, Microsoft OneDrive and Box.
Will synchronization stop when a folder is protected?
The vendor says background sync can remain active while ordinary local access is locked through the application.
Is there a free version?
The desktop software is offered as a limited trial rather than permanent freeware. Continued unrestricted use requires registration.
What is the current price?
The official store showed a one-time price of US$34.95 when this guide was reviewed on July 18, 2026. Check the store again before paying.
Does Cloud Secure replace BitLocker, MFA or Purview?
No. BitLocker protects the Windows drive, MFA strengthens cloud sign-in, Purview can apply document-level policy, and Cloud Secure controls ordinary access to selected local sync folders. They cover different risks.