When you add a work or school account to Windows, or use a company laptop, a reasonable question follows: what can they see? The answers circulating online range from paranoid to naively reassuring. The honest https://saborcitosrestaurant.com/ answer depends entirely on one distinction most people never notice.
The Distinction That Decides Everything
There is a large difference between adding a work account to your personal PC and your PC being managed by the organisation.
Adding an account, to use Teams or Outlook, gives the organisation authority over that account and its data. Enrolling a device in management gives them authority over the machine.
These get conflated constantly, and the difference is enormous. In the first case, they manage a login. In the second, they can manage settings, install software, enforce policies, and in some configurations wipe the device.
What They Can Generally See
On a managed device, an organisation typically can see device information like model, serial number, and operating system version; compliance status such as whether encryption and updates are current; installed applications; and data within their own services, your work email, files in their cloud storage, Teams messages.
That last one deserves emphasis. Anything in company systems is company data. Work email and work-cloud files are theirs, not private, regardless of how personal the content.
What They Generally Cannot See
Standard management tooling does not typically give employers a live view of your screen, your personal browsing history, your keystrokes, or your personal files sitting outside their services.
But note “typically” and “standard”. Dedicated monitoring software exists, and an organisation that installs it on a device they own can capture far more. The limit is not technical impossibility; it is what they have chosen to deploy, plus local law and policy.
How to Check Your Own Situation
Rather than guessing, look. Settings, Accounts, then Access work or school shows whether an account is connected and whether the device is managed. Windows Security’s Device security area may also indicate management.
The Practical Rule
The reliable approach is not technical but behavioural: keep personal things off work devices and work accounts.
Not because you are doing anything wrong, but because the boundary is unclear and shifting, and the effort of proving what they can see exceeds the effort of simply not mixing. A personal device with a work account is a different risk from a company laptop, and treating both as company-adjacent is the simplest defence.
The Takeaway
Adding a work account grants authority over that account; enrolling a device grants authority over the machine, and that gap is where the real answer lives. Company services hold company data regardless of content. Check Access work or school to see your actual situation, and keep the two worlds separate rather than relying on assumptions about what is visible.