Microsoft’s uninvited OneDrive Photos app reads local image folders on Windows 11 before sign-in

Microsoft’s uninvited OneDrive Photos app reads local image folders on Windows 11 before sign-in

A photo organiser with facial grouping reached Windows 11 desktops in late July without a consent screen, a Store listing or a separate uninstall option. The face scanning itself is opt-in and unusually well disclosed. The delivery channel that carried it is neither, and that is the part European and Texan law will eventually test.

On 29 July 2026, Windows Latest reported that Windows 11 machines had acquired a photo application nobody had chosen to install. OneDrive Photos appears in the Start menu and in Windows Search, shows images held on local drives before any Microsoft account has been signed in, and carries a People section that groups faces across a photo library. It arrived through either a Windows Update or an update to the OneDrive sync client, with no first-run notice and no separate uninstall entry.

Most of the alarm since has settled on the face scanning. That is the wrong place to look. Microsoft puts face grouping behind a permission prompt, states in that prompt that the data may count as biometric data in some regions, and commits in its support documentation to deleting grouping data within 30 days of the feature being switched off. The part Microsoft has not documented is the delivery mechanism — how a biometric-capable application reached millions of machines without an announcement, a consent screen, a Store listing, or a route to removal that does not also remove cloud file sync. The scanner is governed. The channel that carried it is not.

A Start menu entry that arrived without an announcement

OneDrive Photos is not a separate download. Windows Latest traced the Start menu shortcut to OneDrive.App.exe inside the OneDrive program directory, sitting beside the sync client’s own executable, OneDrive.exe, in the same folder. The window is built on WebView2, which means the interface is a packaged web experience mirroring the current OneDrive.com layout rather than a native Windows application. Its sections — Moments, Gallery, People, Albums, Favorites and This PC — match the web app, with This PC as the addition that reaches into local storage.

The behaviour before sign-in is what makes the arrival awkward. Windows Latest tested the app on a machine where the bundled OneDrive client had never been signed in to a Microsoft or work account, and the Gallery still populated with local images. The French outlet IT-Connect found the same shortcut pointing at the same executable on one of its own machines, which rules out a single misconfigured test system. Signing in converts the window into a full OneDrive gallery with cloud search attached.

No Microsoft announcement, blog post or Microsoft 365 Message Center entry describing this rollout was identified in the days after the discovery. The absence of a first-run dialogue is the structural fact here, not an oversight in messaging: because the gallery ships as a second mode of software already installed on the machine, an update to that software can add a new Start menu entry without triggering any of the consent surfaces a fresh installation would normally raise. There is no Store library record, no installer, and no changelog for a user to consult.

Windows already includes Microsoft Photos, and the two overlap heavily on viewing, editing, favouriting, printing and setting wallpaper. Duplication alone is a nuisance. Duplication of an app that can read every image folder on a drive, from a client the user may never have opened, is a different category of problem.

The two claims being conflated in the alarm over local scanning

Two distinct pieces of technology are being merged in the way this story is circulating, and separating them changes the conclusion. The first is content recognition for search. Microsoft’s own support page for organising photos states that OneDrive automatically creates tags for things it recognises and lets users edit or remove those tags, and Windows Latest found that cloud search can read visible text inside images to return results. That is optical character recognition and object tagging, it operates on material in the cloud after sign-in, and it long predates this app.

The second is facial grouping, which builds a template distinguishing one person from another across a library. Microsoft’s documentation is blunt about what that involves: the company collects, uses and stores facial scans and biometric information from photos through the OneDrive app for facial grouping technologies. Optical character recognition does not detect or match faces, and describing face grouping as an OCR process misstates both the mechanism and the legal category of the data. One reads text. The other creates a biometric identifier.

The claim that the app silently walks every folder hunting for faces also does not survive contact with the reporting. The People section presents a permission prompt before grouping begins, and that prompt carries an explicit warning that the resulting data could be considered biometric data in some regions. Microsoft says groupings are visible only to the account holder, are not shared when a photo or album is shared, and are not used to train its models generally.

What deserves scrutiny is a smaller and stranger detail. Microsoft’s support article on grouping photos by people still carries a note saying the feature is coming soon and yet to be released, on a page last published in March 2026, while the feature ships inside an app on end-user desktops. Documentation that lags the product by this much is not a rounding error when the subject is biometric processing.

One executable, two products, and no clean way to separate them

The removal path is where the design turns from untidy into consequential. Because the gallery runs from the OneDrive installation rather than as a registered application of its own, Windows Latest concluded that blocking it means removing OneDrive entirely through Settings and Installed apps. For a home user who keeps holiday photographs on a local drive, that is an easy trade. For an organisation running Known Folder Move, Teams file sharing and SharePoint document libraries through the same client, it is not a trade at all.

Reporting is not unanimous on this point, and the disagreement matters. At least one outlet describes an Uninstall option appearing for OneDrive Photos in the Installed apps list on some machines, while advising that where no such entry exists the OneDrive client itself has to go. Windows Latest found no independent removal route. The available public evidence does not establish whether an independent uninstall entry exists on some builds and not others, or whether it appears only under particular client versions, and Microsoft has published nothing that would settle it.

The distinction is not cosmetic. An application that can be uninstalled is an application an administrator can inventory, approve, deny and audit. An execution mode inside another binary is none of those things. Software asset tools that key on installed application names will not see OneDrive Photos at all; only a check against the executable path will find it. That is a gap in the basic hygiene most security programmes assume they have.

The dependency also runs in an uncomfortable direction. OneDrive is not an optional download on Windows; it ships with the operating system and its folder backup prompts appear during setup. A feature bundled into a component that arrives with the platform inherits the platform’s reach, while escaping the platform’s servicing controls. That combination is what makes this more than another unwanted photo viewer.

The incentive to ship features through a client that updates itself

Consider why an engineering organisation would choose this route. The OneDrive client updates on its own cadence, independently of the monthly Windows servicing cycle that enterprises test, stage and defer. Anything delivered through it reaches machines faster and encounters fewer administrative gates. That is a real advantage for a company under pressure to put artificial intelligence features in front of users, and the pattern is visible elsewhere in Microsoft’s recent history: the Microsoft 365 Copilot app’s default installation was paused in early 2026 after complaints, then resumed in June 2026 through the Office Click-to-Run channel, a delivery route separate from the blockers administrators had applied to Windows Update.

The commercial logic behind a photo gallery specifically is straightforward. Photo libraries are among the largest personal data sets people hold, and storage is what OneDrive sells. A gallery that indexes local pictures, shows them next to cloud pictures, and offers search that works properly only once an account is attached is an on-ramp. Reading this as an engagement and storage-attachment play rather than a surveillance project is the interpretation the evidence best supports, and it is worth saying plainly, because the surveillance framing lets Microsoft off the hook on the point that actually stands up.

That point is governance. Nothing in the incentive structure rewards publishing a Message Center notice, a policy control or an architecture description before shipping. The features arrive; the documentation, the admin templates and the regulatory analysis follow whenever they follow. Recall showed what happens when that sequence collides with public scrutiny — the snapshot feature was delayed in June 2024, rebuilt, made explicitly opt-in, and given the ability to be removed through optional features.

The lesson Microsoft took from Recall was about the feature’s defaults. The lesson it did not take was about how features get onto machines in the first place.

Consent that changes shape depending on where the user lives

Microsoft’s grouping documentation contains a sentence that carries more weight than its placement suggests: some regions require the user’s consent before processing of photos can begin. Read as a statement of engineering behaviour, it means the feature’s default posture is geographic. Where law compels a prior opt-in, there is one. Where it does not, the processing can start and the user’s control becomes a switch to be found later.

European law is the reason for the split. Article 9 of the General Data Protection Regulation prohibits processing biometric data for the purpose of uniquely identifying a natural person unless a specific condition applies, and for a consumer photo service the realistic condition is explicit consent under Article 9(2)(a). That sits on top of a separate lawful basis under Article 6, and both layers have to hold. A facial template built to tell one person from another across a library is squarely inside the category.

The 2025 preview of the same feature showed how badly the mechanics can be handled. Users who received early access found grouping switched on by default, with a notice stating that OneDrive uses artificial intelligence to recognise faces in their photos, and a follow-up warning that the setting could be turned off only three times a year. Microsoft declined to explain the cap when asked, and told Slashdot only that OneDrive inherits privacy features and settings from Microsoft 365 and SharePoint where applicable. Commenters proposed a benign explanation, that repeated toggling forces expensive regeneration and deletion of biometric data in jurisdictions where deletion is mandatory. That explanation, even if correct, describes a cost problem being solved by capping a data subject’s ability to withdraw consent, which is close to the opposite of what the regulation requires.

There is a further group with no switch at all. A personal photo library contains children, relatives, colleagues, neighbours and strangers caught in the background of a public scene. The account holder consents; the people whose faces are templated are not asked.

The compliance step that cannot be finished before the software is running

For any European organisation whose devices hold photographs — schools, clinics, estate agents, media teams, human resources functions with staff portraits — biometric processing at scale triggers a data protection impact assessment. That assessment has to describe where processing happens, what leaves the device, which entity acts as controller and which as processor, and where the data is stored. Microsoft has not published whether the facial analysis behind grouping runs locally, in its cloud, or in some combination, and that single omission blocks the assessment.

The practical position is therefore inverted. Software capable of biometric processing is already sitting in the Start menu on managed endpoints while the paperwork that is supposed to precede such processing cannot be completed. An administrator who wants to act finds the OneDrive administrative templates for Group Policy and Intune available and documented, but no published control specific to OneDrive Photos or to the grouping feature within it. The blunt instruments — blocking sync entirely, or removing the client — carry their own damage.

What Microsoft has published and what it has not

ElementPublished positionLeft unstated
Rollout channelNoneHow the app was pushed and to which builds
Face grouping consentPermission prompt in People; prior consent in some regionsWhich regions, and the default elsewhere
Biometric retentionDeleted within 30 days of switching offRetention while active, and backup copies
Processing locationNoneWhether analysis runs on device or in the cloud
Model trainingNot used to train models generallyScope of per-account result tuning
Independent removalNoneWhether a standalone uninstall exists

The pattern in the right-hand column is consistent: everything Microsoft has documented concerns what the feature does once a user has agreed to it, and everything left unstated concerns how the software got there and where the data goes. Those are the two questions a regulator asks first.

Enterprises have a second exposure through folder backup. If Pictures, Desktop or Documents were ever enrolled in OneDrive folder backup — the setting Windows setup pushes by default — then images from those folders are already in a cloud account where the grouping feature can reach them. Checking which folders are enrolled is a faster diagnostic than auditing the app itself.

The case for treating this as ordinary product plumbing

The strongest defence of Microsoft’s position deserves stating properly, because parts of it hold. Face grouping in consumer photo services is not new or exotic: Google Photos has grouped faces since 2015, and Apple’s Photos performs comparable identification on the device. OneDrive has recognised image content and generated tags for years. What shipped in July was a front end onto cloud features that already existed, not a new capability aimed at users’ faces.

The disclosure is also better than the sector norm. Few companies write, in plain language on a support page, that they collect, use and store facial scans and biometric information. Fewer still commit to a deletion window, state that groupings are never exposed when an album is shared, and confirm that the data is not used to improve a general model. Microsoft did all three before the app appeared, and the People prompt repeats the biometric warning at the moment of decision. On the substance of the feature, the company’s conduct is defensible.

Nor is there evidence for the most serious version of the accusation. No reporting has shown facial analysis running on local files before sign-in, or grouping proceeding despite a declined prompt. The gallery reads local images to display them, which is what a photo viewer does. Windows Latest’s own assessment was that the app performs well and is not unpleasant to use.

Where the defence fails is on process, and process is what the law polices. A permission prompt inside an application the user did not install and cannot separately remove is consent operating on ground the user did not choose. Regulators have shown repeatedly that they treat the conditions surrounding consent as part of the consent. Good disclosure attached to an undisclosed distribution channel is a partial answer, and the missing half is the half that generates liability.

Decisions facing administrators and households this week

For an individual, the sequence is short. Search the Start menu for OneDrive Photos to establish whether it is present. Open the OneDrive settings from the system tray and check, under account and folder choices, whether Pictures, Desktop or Documents are enrolled in backup, because that determines whether a personal library is already in scope for cloud processing. If the People prompt has been accepted, grouping can be switched off under privacy and permissions in OneDrive settings, with Microsoft’s stated deletion window of 30 days then applying. Where the irritation is simply that images open in the wrong application, changing the default image viewer is the lower-cost fix.

For an organisation, the choice is a genuine trade rather than a checklist. Inventory by executable path rather than application name, because tooling keyed to installed-app records will not see this. Then decide whether biometric-capable software on endpoints holding photographs is tolerable while the processing location is undocumented. If it is not, blocking sync through the OneDrive administrative templates or removing the client are the available levers, and both break folder backup and parts of the Teams and SharePoint file experience. Carving exceptions by device group is usually cheaper than a fleet-wide block.

Three actions cost almost nothing and are worth taking regardless. Record the data protection impact assessment gap in writing, with the date, so the file shows the question was asked before the software was in production rather than after. Put the processing-location question to the Microsoft account team in a form that requires a written answer. And add a standing check for new Start menu entries introduced by client updates rather than by Windows Update, since this rollout demonstrated that the second channel exists and is not covered by the controls most organisations rely on.

Regulated sectors handling images of patients, pupils or vulnerable people should treat the undocumented processing location as disqualifying until answered, not as an open question to be resolved later.

The precedent that outlives the People toggle

The durable issue is not the face scanner, which can be declined, switched off and deleted. It is that a component shipping with Windows became a route for placing new software on machines outside the mechanisms designed to govern exactly that. Once that route is established and unpunished, it will be used again.

European law has a provision aimed at this shape of problem. The Commission designated Microsoft as a gatekeeper on 5 September 2023 in relation to Windows PC OS, and Article 6(3) of the Digital Markets Act requires a gatekeeper to allow and technically enable end users to easily uninstall software applications on its operating system, subject to a narrow carve-out for software essential to the functioning of the system. A photo gallery is not plausibly essential. If the only way to remove it is to remove cloud file synchronisation, the question raises itself. No Commission proceeding on this point had been opened at the time of writing, and none may be; the observation is that the legal hook already exists and does not require new rulemaking.

The American exposure is priced rather than theoretical. Texas secured $1.4 billion from Meta in July 2024 over facial recognition data collected without the consent its Capture or Use of Biometric Identifier Act requires, and $1.375 billion from Google in a settlement agreed in May 2025 and finalised on 31 October 2025 covering biometric identifiers among other claims. That statute allows $25,000 per violation. A consumer photo library multiplied by a per-violation figure is the arithmetic that makes biometric consent a board-level matter, whatever the engineering merits of the feature.

Three developments would weaken the criticism made here: Microsoft publishing where facial analysis runs, a standalone uninstall entry appearing reliably in Installed apps, and an administrative template that controls the gallery without disabling sync. One development would confirm it. If the next artificial intelligence feature reaches Windows desktops the same way — through a self-updating client, with the documentation arriving afterwards — then July 2026 was not an oversight but a method.

Straight answers about OneDrive Photos, face grouping and how to regain control

What is OneDrive Photos and where did it come from?

It is a photo viewing and organising interface that began appearing in Windows 11 Start menus in late July 2026. It is not a standalone installation: it runs from OneDrive.App.exe inside the OneDrive program folder and arrived through either a Windows Update or an update to the OneDrive sync client.

Did Microsoft install it without permission?

Effectively, yes. It appeared without an announcement, without an installation prompt and without a Microsoft Store library entry, including on machines where the bundled OneDrive client had never been signed in to any account.

Does it scan all my photos for faces automatically?

No. The People section presents a permission prompt before facial grouping begins, and the prompt warns that the data may be treated as biometric data in some regions. Microsoft’s documentation notes that some regions require consent before processing starts, which implies the default differs elsewhere.

Is the face grouping done with OCR?

No. Optical character recognition reads text visible inside an image and feeds search results. Facial grouping builds a template that distinguishes individuals across a library. They are separate systems performing unrelated tasks, and only the second involves biometric data.

Where does the facial analysis actually happen?

Microsoft has not published whether the analysis runs on the device, in its cloud, or both. That omission is the main obstacle for any organisation that has to complete a data protection impact assessment before biometric processing takes place.

Can I uninstall OneDrive Photos on its own?

Windows Latest found no independent removal route and concluded that removing OneDrive itself is required. Some reports describe an uninstall entry appearing for the app on certain machines. The public evidence does not settle which builds behave which way.

Does Microsoft use my face data to train its AI models?

Microsoft states that facial scans and biometric information are not used to train or improve the AI model overall, and that any data provided is used only to improve results within that individual account.

How do I turn face grouping off and what happens to the data?

The setting sits under privacy and permissions in OneDrive settings, in the People section. Microsoft states that all facial grouping data is permanently removed within 30 days of the feature being switched off, and that data is also deleted after a period of account inactivity.

Is this the same situation as Windows Recall?

The pattern rhymes rather than repeats. Recall captured screen snapshots and was delayed in June 2024, rebuilt, made opt-in and given a removal path after public criticism. OneDrive Photos involves a narrower data type but the same sequence: a capability arriving quietly, then being explained after journalists found it.

What should an IT administrator do first?

Inventory by executable path rather than application name, check whether Pictures, Desktop or Documents are enrolled in OneDrive folder backup, and record the unanswered processing-location question in writing before deciding whether to block sync through the OneDrive administrative templates.

Author:
Jan Bielik
CEO & Founder of Webiano Digital & Marketing Agency

Microsoft's uninvited OneDrive Photos app reads local image folders on Windows 11 before sign-in
Microsoft’s uninvited OneDrive Photos app reads local image folders on Windows 11 before sign-in

This article is an original analysis supported by the sources cited below

Windows 11 is quietly installing OneDrive Photos, and it wants to scan your photos for faces if you allow it
The original discovery and hands-on testing, establishing the OneDrive.App.exe path, the WebView2 basis, the app’s sections, its behaviour before sign-in, the OCR-driven cloud search, the People permission prompt and the absence of an independent uninstall route.

Group photos by people in Microsoft Photos
Microsoft’s own statement that it collects, uses and stores facial scans and biometric information through the OneDrive app, that groupings stay private, that the data is not used for general model training, that deletion follows within 30 days of switching off, and that some regions require consent before processing begins. Also the page still labelling the feature as coming soon.

Organize and find photos in OneDrive
Documents the automatic content tagging and location-based search that predate the new app, supporting the separation between content recognition and facial grouping.

Windows 11 OneDrive Photos installs itself without asking
Independent confirmation on a second journalist’s machine that the Start menu entry points to OneDrive.App.exe, plus the observation that the underlying grouping capability existed before this app.

OneDrive Photos silently installs on Windows 11 with biometric scan capability, no removal path
Sets out the enterprise consequence of the missing processing-location disclosure, the absence of policy controls specific to the app, and the Microsoft 365 Copilot installation being paused in early 2026 and resumed in June 2026 via Office Click-to-Run.

Windows 11 installs OneDrive Photos uninvited
The competing account describing an uninstall option available through Windows Settings on some machines, which is the basis for treating the removal question as unresolved.

Privacy alert – OneDrive Photos revives Windows Recall concerns
An administrator-facing reading of the rollout, itemising the app’s availability without an account, the OCR and People features after sign-in, and the removal dependency on the sync client.

Preview users have noticed OneDrive’s AI-driven face recognition setting is opt-out, and can only be turned off three times a year
Documents the 2025 preview behaviour, the default-on posture and the three-times-a-year revocation cap, together with the deletion-cost explanation circulated by commenters.

Microsoft OneDrive limits how often users can restrict facial recognition setting
Records the in-app privacy notice wording, the support page’s coming-soon label as it stood in October 2025, and the comparison with Google’s and Apple’s earlier face-grouping features.

Microsoft OneDrive limits how often you can adjust its facial recognition setting
Source of Microsoft’s statement that OneDrive inherits privacy features and settings from Microsoft 365 and SharePoint, and of the company declining to explain the toggle limit.

Art. 9 GDPR – Processing of special categories of personal data
The prohibition on processing biometric data for the purpose of uniquely identifying a natural person, and the explicit-consent condition that lifts it.

Commission decision designating Microsoft as a gatekeeper under the Digital Markets Act
The Commission’s decision of 5 September 2023 establishing that Windows PC OS and LinkedIn are designated core platform services, which is what brings the operating system inside the Article 6 obligations.

Digital Markets Act, Article 6
The text of Article 6(3) requiring gatekeepers to allow and technically enable easy uninstallation of software applications on the operating system, with the carve-out for software essential to its functioning.

Attorney General Ken Paxton secures $1.4 billion settlement with Meta over its unauthorized capture of personal biometric data
The July 2024 settlement figure and the fact that it was the first action brought under the Texas Capture or Use of Biometric Identifier Act.

Attorney General Ken Paxton finalizes historic settlement with Google and secures $1.375 billion
Confirms the Google settlement amount, its coverage of biometric identifiers alongside geolocation and browsing claims, and the 31 October 2025 finalisation date.

Texas AG’s billion-dollar settlement with Google highlights biometric data use compliance considerations
Establishes the $25,000 per-violation damages figure available under the Texas statute and the attorney general’s broad reading of its scope.

Update on Recall security and privacy architecture
Microsoft’s own account of Recall as an opt-in experience that can be removed through optional features, used here as the comparison case for how the company responds to privacy criticism.

Citing this article? Brief excerpts are welcome. Please credit Webiano.digital, name the author where stated, and include a link to https://webiano.digital and to this original article. Full or substantial republication requires prior written permission. Read our Copyright and Content Use Policy.

This article was prepared with the assistance of artificial intelligence tools. The content underwent expert human review, and Webiano Digital & Marketing Agency assumes editorial responsibility for its final version and publication.