Skip to content

CyberGrant protects every aspect of your digital security

Discover the modular solutions designed to protect your company from external and internal threats, as well as new challenges like AI.

key-minimalistic-square-3-svgrepo-com

Digital asset protection

Automatic classification

Cloud encryption

Email protection

Anti-phishing

password-minimalistic-input-svgrepo-com

Remote access

Access rules

Credentials

Stolen Device

Web access

email grant

Post-send control

Protected Attachments

Human error

Advanced encryption

laptop-svgrepo-com (1)

Beyond Antivirus

External Threats

Data Exfiltration

Remote Work

Zero trust

pulse-svgrepo-com

Device control

Shared files

Audit Trail

Credential Access

Email Channel

Anomaly detection

password

Company vault

Controlled sharing

Zero-trust encryption

Logging and generation

share

Third-party users

RBAC

Anti-AI scraping

VDR

medal-ribbons-star-svgrepo-com

GDPR and encryption

NIS2

DORA

AI act

Audit

bot-svgrepo-com

AI control

Automated classification

AI blocking

Private AI

magnifer-bug-svgrepo-com

Attack Surface Mapping

Penetration testing

Ransomware

Human Factor

After the Test

Tailored cybersecurity for every business.
Scalable solutions compatible with legacy systems, designed for both SMEs and large enterprises requiring full control over data, access, and sharing.


IT
Consulting
Travel
Advertising

Construction
Real Estate

Oil & Gas
Electricity
Telco

E-commerce
Transportation
Shipping
Retail chains

Design
Automotive
Industrial

Central agencies
Local agencies
Supranational orgs

Discover security features to protect your data, files, and endpoints

FileGrant
FileGrant

Securely store, share, and manage your files with an advanced, easy-to-use, and highly customizable platform

 

SG_pittogramma_blu
SecretGrant

Control every credential like a file. Share, track, and revoke access instantly.

 

RemoteGrant
RemoteGrant

RemoteGrant protects your business from attacks and data loss by enabling employees to securely access workstations and files from anywhere.

 

EmailGrant
EmailGrant

Encrypt every email and keep control of attachments, even after sending.

 

AG_pittogramma_blu
AIGrant

AIGrant is your personal assistant - it understands your data, keeps it secure, and delivers exactly what you need.

 

Connector CyberGrant
Connector

Encrypts every file on SharePoint and OneDrive, in any format, leaving your libraries, permissions, and daily workflows untouched.

 

EncryptSharePoint
Valerio PastoreAug 31, 2026, 5:03:03 PM9 min read

How to encrypt SharePoint files without replacing it or migrating

How to encrypt SharePoint files without replacing it or migrating
12:33

SharePoint doesn't encrypt your files. And Purview doesn't do what you think.

Ninety-eight percent of the Italian organizations we work with run SharePoint. Almost none of them have encrypted the files stored on it. The problem isn't negligence. It's a wrong assumption: that managing access permissions is the same as protecting the file. It isn't. This article explains the difference and what it takes to close the gap.

The short version

  • SharePoint manages access permissions, not file encryption. An authorized user can download a document and take it anywhere: outside the company, onto a personal device, onto an ungoverned cloud service. That file is readable.
  • Microsoft Purview, bundled in the E5 package at roughly €150 per user per year, encrypts Office files. For everything else, it either leaves the file unprotected or changes the extension: a JPEG becomes PJPEG, a TXT becomes PTXT. Those files won't open in Photoshop, Notepad, or Adobe Reader.
  • The CyberGrant Connector for SharePoint encrypts every file format, preserves the original extension, supports in-browser and local editing with no extra steps, and requires zero document migration.
  • Protection follows the file even when it syncs to a personal device: if the device isn't authorized, the file downloads but won't open.
  • The Azure admin cannot open files protected by the Connector. The segregation is real.
  • Encryption uses CRYSTALS-Kyber, the post-quantum standard NIST FIPS 203 (August 2024).

 

What does SharePoint actually protect?

If you manage SharePoint for a mid-to-large organization, you've probably answered the same question dozens of times: "Are our SharePoint files secure?" The honest answer depends on what you mean by secure.

SharePoint protects access: who can enter, read, modify, download. It's a collaboration and document governance tool, and on that front it works well. The problem starts when you assume that protecting access is the same as protecting the file.

The moment a document leaves the SharePoint perimeter (as a download, an email attachment, a OneDrive sync, or a USB copy) the content is readable. Not because something failed: that's exactly how it's supposed to work. SharePoint did its job, which was to check who had permission to download. After that, the protection ends.

The 2026 Verizon Data Breach Investigations Report puts 62% of breaches down to a human element, with 48% involving a third party or vendor. In both cases, the access was usually legitimate: an employee taking files home, an external contractor syncing a project folder, a departing collaborator with documents already downloaded weeks earlier. SharePoint doesn't flag those scenarios because they aren't anomalies. They're normal operations.

This isn't a criticism of SharePoint. It's a description of what it wasn't designed to do.

 

Does Purview encrypt all files on SharePoint?

Microsoft's answer to this gap is Microsoft Purview, bundled in E5. The answer is partial, and understanding where it stops is more useful than knowing where it starts.

Purview encrypts Office files: Word, Excel, PowerPoint, Outlook. For those formats, the protection works, with some caveats on external sharing covered below.

For everything else, the behavior changes. A JPEG uploaded to a Purview-protected SharePoint site becomes PJPEG. A TXT becomes PTXT. Opening those files requires Microsoft's proprietary viewer: Photoshop won't recognize them, Notepad won't open them, Adobe Reader won't work without a complex integration. Any organization working with design files, CAD drawings, PDFs, source code, or any non-Office format faces a hard choice: leave those files unprotected, or accept that users can no longer open them with their usual tools.

There's a second limitation, less visible but significant in many environments. A privileged Azure tenant administrator can open Purview-encrypted files. That's not a bug. It's Microsoft's trust model. In an organization where the Azure infrastructure is managed by an external service provider, or where you want to separate data custody from tenant administration, that becomes a real problem.

The third limitation is external sharing. Sending a Purview-protected file to a collaborator outside the company requires creating an account in the sender's Azure system. It's not impossible, but it adds an onboarding step that often slows down sharing or gets bypassed.

 

How the CyberGrant Connector for SharePoint works

The CyberGrant Connector for SharePoint brings file-centric protection directly into the SharePoint and OneDrive environment. Files stay where they are: no migration, no library changes, no modifications to the permission policies the organization has spent years configuring.

The logic is the same we use for network shares with RemoteGrant: files are encrypted automatically on upload, according to rules defined at the site or folder level. The organization decides which areas to protect. The rest of the SharePoint environment stays unchanged.

In-browser opening. Encrypted files open directly from SharePoint in the browser, through FileGrant, using the Microsoft authentication already integrated. The user doesn't switch interfaces, doesn't authenticate to a separate system. They see the file, open it, edit it.

Local opening. Users who sync files through OneDrive open them locally with a double-click, the same way they always have. RemoteGrant intercepts the open request, decrypts in memory, and the document opens in the native application. No temporary copy is written to disk: when the file closes, no trace of the decrypted content remains locally.

Every format, no exceptions. JPEG with Photoshop, PDF with the corporate reader, PSD, AutoCAD, source code: the Connector encrypts any format and preserves the original extension. An encrypted JPEG stays JPEG. A developer who wants to open a text file with Notepad can. A designer who wants to open a PSD with Photoshop can. The content is protected; the workflow isn't.

Inline editing and library save. Opening, editing, and saving an encrypted document requires no extra steps. Changes are written directly to the SharePoint library, in the updated and still-encrypted version. No decrypt-edit-re-encrypt-re-upload cycle. You open, edit, save.

External sharing without Azure accounts. From SharePoint, a right-click lets you share an encrypted file with an external collaborator through FileGrant. The recipient gets the document with all protections active: screenshot blocking, copy-paste blocking, post-sharing revocation. No Azure account needed.

Protection from the Azure admin. Data segregation from the infrastructure is an architectural property, not a configurable policy. The Azure admin cannot open files protected by the Connector, even with full tenant privileges. Data custody and infrastructure administration stay separate.

 

What changes for the CIO

The first shift is in how you think about managed service providers. If your Azure tenant is managed by a third party, sensitive content protection no longer depends on trusting that provider. The files are encrypted: even someone with full administrative access to the tenant cannot open them.

The second concerns unauthorized devices. Today, a user who syncs SharePoint to personal OneDrive takes company files outside the controlled perimeter. With the Connector, that file syncs normally but won't open on an unrecognized device. The content is unusable without the right context.

The third is workflow. With Purview, anyone who wants to modify a non-Office file has to manually unprotect it before opening it in the native application, then re-protect it when done. With the Connector, that cycle doesn't exist. Open, edit, save. Protection doesn't interrupt work.

 

Post-quantum encryption on SharePoint files

The Connector's encryption uses CRYSTALS-Kyber, the post-quantum standard defined by NIST in FIPS 203 (ML-KEM), published August 2024. It's the same standard we use across the entire FileGrant suite.

Why this matters for SharePoint. Files stolen today in encrypted form can be decrypted once a sufficiently powerful quantum computer becomes available. That's the "harvest now, decrypt later" logic: someone collects the data now and waits. For files with long-term value (multi-year contracts, intellectual property, clinical records) the threat horizon isn't distant. It's already relevant when choosing the encryption you adopt today.

Microsoft Purview does not offer post-quantum encryption.

For a deeper look at the file-centric protection model underlying this architecture: Traditional DLP is obsolete: the limits exposed by NIS2. For the technical perspective on the post-quantum transition: How to prepare for the post-quantum future.

For full technical specifications of the Connector: CyberGrant Connector for SharePoint.

If you want to see it in action, you can request a demo.

 

Frequently asked questions about the CyberGrant Connector for SharePoint

How does the CyberGrant Connector encrypt files on SharePoint?

Encryption is automatic. Rules are defined at the SharePoint site or folder level, and every file uploaded to a protected area is encrypted with CRYSTALS-Kyber (NIST FIPS 203) without any user action. Existing SharePoint permission policies stay unchanged; only the level of content protection changes. No document migration or library restructuring is required.

Can encrypted SharePoint files be opened and edited with standard business applications?

Yes, across every format. A JPEG opens with Photoshop, a PDF with the corporate reader, an AutoCAD file with its native software, a text file with Notepad. The Connector never changes file extensions. Editing happens directly in the browser or locally through RemoteGrant: changes save back to the SharePoint library with no extra decryption or re-upload steps.

What are the main differences between the CyberGrant Connector for SharePoint and Microsoft Purview?

Microsoft Purview encrypts Office files (Word, Excel, PowerPoint). For other formats, it changes the extension (JPEG becomes PJPEG) and requires a proprietary viewer. The Connector CyberGrant encrypts all formats without changing extensions. Purview offers no post-quantum encryption; the Connector uses CRYSTALS-Kyber (NIST FIPS 203). Purview requires creating an Azure account for external sharing; FileGrant needs only a right-click from SharePoint. A Purview-protected file is accessible to the Azure admin; a Connector-protected file is not.

Can an Azure administrator access files encrypted by the Connector?

No. Exclusion of the Azure tenant administrator is an architectural property of the Connector, not a configurable policy. Even with full privileged access to the tenant, the admin cannot open or export protected files. This allows organizations to separate data custody from infrastructure administration, a requirement increasingly relevant when the tenant is managed by an external provider.

How do you share an encrypted SharePoint file with someone outside the company?

From SharePoint, right-clicking an encrypted file starts the sharing flow through FileGrant. The recipient receives the document with all protections active: screenshot blocking, copy-paste blocking, post-sharing revocation. No Azure account is required for the recipient. Access to the document can be revoked at any time after sharing.

Does the Connector require migrating existing documents?

No. Files remain in existing SharePoint libraries. No structural changes, no permission redefinitions, no user retraining. The organization decides which sites or folders to protect; from that point, newly uploaded files in those areas are encrypted automatically. Everything else in the SharePoint environment stays unchanged.

What happens if a user opens an encrypted file on a personal device?

The file syncs normally through OneDrive but will not open on an unauthorized device. The encryption makes the content unusable without a device recognized as authorized by the organization. This applies to personal laptops used for remote work as well.

avatar
Valerio Pastore
Valerio Pastore is a cybersecurity expert and patent inventor in the data protection field. Founder of CyberGrant, he's developed innovative technologies for Data Loss Prevention (DLP), AI-driven security, and quantum-proof encryption, as well as advanced anti-scraping systems.

ARTICOLI CORRELATI