Microsoft Places – Data Privacy / Historical User Data

Pospiech, Jan Nikolas 0 Zuverlässigkeitspunkte
2026-09-30T07:48:46.11+00:00

Microsoft Places – Data Privacy / Historical User Data

We are currently evaluating Microsoft Places from a German data protection and works council perspective.

We need clarification regarding historical and personally identifiable workplace data.

  1. Can a Places Administrator or Places Analytics user view historical work-location information for an individual employee?
  2. Can an administrator search for a specific employee and see on which days the employee was in a particular office/building?
  3. Are historical work-plan, workplace-presence or check-in data stored with the user's identity/name?
  4. Can individual desk reservations be historically associated with a specific employee?
  5. Can Places Analytics display personally identifiable information, or are analytics only available in aggregated form?
  6. Can Places Analytics data be filtered down to an individual employee?
  7. Can personally identifiable Places data be exported via UI, PowerShell, Microsoft Graph or another API?
  8. How long are the following data types retained:
    • Work Location
      • Work Plan
        • Workplace Presence
          • Workplace Check-in
            • Desk reservations
              • Room reservations
                • Places Analytics data
                  • Wi-Fi/network occupancy signals
                    • Badge signals
                      • Sensor signals
                      1. Are identifiers in Places Analytics anonymized, pseudonymized or directly associated with Microsoft Entra ID identities?
                      2. Is there a minimum aggregation threshold that prevents administrators from identifying individual employees from Places Analytics?
                      3. Can retention periods for these data types be configured by the customer?
  9. Which Microsoft Purview retention, audit, eDiscovery or data-subject-request capabilities apply specifically to Microsoft Places data?
Microsoft Teams | Microsoft Teams für Unternehmen | Andere
0 Kommentare Keine Kommentare

1 Antwort

Sortieren nach: Neueste
  1. Aetherin 2,495 Zuverlässigkeitspunkte Unabhängiger Berater
    2026-09-30T08:40:57.3133333+00:00

    (This is a German forum, but I noticed that you originally posted your question in English, so please allow me to reply in English to make the discussion easier and smoother for us.) 

    Hello @Pospiech, Jan Nikolas,

    Based on the current Microsoft documentation, I would like to address each of your questions below:

    1/Can a Places Administrator or Places Analytics user view historical work-location information for an individual employee?

    No for actual work location generated by workplace check-in. It is cleared after the user’s working hours, and historical actual-location information is unavailable. Refer to Configure workplace check-in.

    2/Can an administrator search for an employee and see their office attendance by day?

    No such Places report is documented. Microsoft also states that workplace check-in does not provide administrators with monitoring or reporting views and is not designed for attendance monitoring.

    3/Are work-plan, actual work-location, or check-in data stored with the user’s identity?

    Work plans are user-associated and are combined with employee profile data for Places Analytics. Actual work location is associated with the user while active; it is cleared at the end of the user’s working hours, and historical actual-location information is unavailable.

    4/Can desk reservations be historically associated with an employee?

    Yes. Desk reservations are Exchange-backed booking records and may identify the booking user. However, Places does not document an employee-level reservation-history report.

    5/Can Places Analytics display personally identifiable information?

    Microsoft states that Places Analytics aggregates data points and does not allow analytics users to identify information about specific employees. However, identifiable Entra ID profile and badge data can be used during source-data processing.

    6/Can Places Analytics be filtered to an individual employee?

    No employee-level filter is documented. Documented analytics focus on buildings, rooms, desk pools, and organizational or leader structures.

    7/Can personally identifiable Places data be exported?

    Microsoft documents no Places Analytics UI, PowerShell, or Graph function for exporting an individual employee’s historical location or check-in history. Exchange-backed reservation records may be searchable or exportable through applicable Exchange and Microsoft Purview tools.

    8/How long is each data type retained?

    • Actual work location generated by workplace check-in: Cleared after the user’s working hours; historical actual-location information is unavailable.
    • Room Call Record Summarized signal: Becomes available within four days after the event and remains available for 28 days.
    • Uploaded badge data: Retained for 28 days.
    • Aggregated processed building analytics data: Retained for 90 days.
    • Work plans, desk/room reservations, Wi-Fi check-in signals, and other sensor datasets: No single general Places-specific retention period is documented. Exchange-backed desk and room reservation records may be subject to applicable Exchange or Microsoft Purview retention policies or eDiscovery holds, depending on the customer’s licensing and configuration.

    9/Are Analytics identifiers anonymous, pseudonymous, or linked to Entra ID?

    Some source datasets contain direct Entra ID identifiers, including ActorId, SMTP addresses, employee-building mappings, manager mappings, and identity information included in badge telemetry. Microsoft does not state that all underlying Places data is fully anonymized. Analytics output is documented as aggregated.

    10/Is there a minimum aggregation threshold?

    Microsoft documents several privacy thresholds: leaders with fewer than 10 members are excluded from the leader hierarchy; days with fewer than 10 employees attending a building are excluded from actual building occupancy dashboards; and desk pools with fewer than 10 desks are excluded from desk-pool analytics. Microsoft does not document one universal threshold applicable to every Places Analytics view.

    11/Can customers configure retention periods?

    No Places-specific retention setting covering these data types is documented. For desk and room reservations, retention is governed by the Exchange and Microsoft Purview configuration described above.

    12/Which Purview, Audit, eDiscovery, and DSR capabilities apply?

    Places inherits Microsoft 365 compliance capabilities where applicable. However, Microsoft does not publish dataset-level Purview coverage for every Places signal. Exchange-backed reservations may be covered by Exchange retention, Microsoft Purview eDiscovery, holds, and applicable DSR processes.

    I based the information above on the following Microsoft documentation:

    For retention periods not explicitly documented above, and for exact Microsoft Purview coverage of Wi-Fi, third-party sensor, and other Places Analytics datasets, written clarification should be requested from Microsoft Support or the organization’s Microsoft account team.

    I hope this information helps clarify your questions. Thank you for your time.


    If the answer is helpful, please kindly click "Yes" button below. If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  

    War diese Antwort hilfreich?


Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.