The Associated Press reported this week on workers whose activity data was used to pressure them over appointment times, review teaching feedback, and measure warehouse throughput. The reporting is grounded by a May investigation from researchers at Northeastern University, Vanderbilt University, UC Berkeley Law, and Columbia Law School, which examined the data flows of nine commonly used monitoring platforms rather than relying on their privacy-policy language.
That distinction is important. The researchers did not establish that every employer secretly watches every employee, nor that Microsoft 365 itself is equivalent to dedicated surveillance software. They did establish something more concrete: when organizations deploy purpose-built monitoring tools, data does not necessarily remain between employer and employee. The monitoring product can become another data-sharing intermediary.
Nine Monitoring Platforms, Hundreds of Outside Destinations
The research team tested Apploye, Deputy, Desklog, Hubstaff, Monitask, Buddy Punch, Time Doctor 2, Vericlock, and When I Work by setting up accounts and observing what their web and mobile products transmitted. All nine shared identifying worker information in at least one observed session, including names, email addresses, and employer information.
Across the sample, the team logged 121 instances of identifying employee data being shared with third parties. It also found 145 unique third-party domains receiving online-activity data, including IP addresses, device details, visited pages, and persistent identifiers. The destinations named by the researchers included Facebook, Google, Microsoft, LinkedIn, Stripe, and Yandex.
Being named as a recipient does not mean Microsoft was operating the monitoring platforms or buying employee dossiers. Third-party services can receive data for advertising, analytics, authentication, embedded widgets, fraud prevention, payments, or other technical functions. But that is not a trivial distinction for workers: an email address and device identifier are precisely the kinds of data that can make records linkable across systems.
The researchers’ sharper finding is that public disclosure often failed to describe what their testing observed. Only two of the nine companies identified specific third parties in their public-facing terms or privacy materials, according to the investigation. Even those disclosures covered only part of the observed data sharing.
For an IT department, this creates a procurement problem as much as a privacy problem. A vendor security questionnaire that asks only whether the product encrypts data, supports single sign-on, or has a SOC 2 report can miss the question that matters most to staff: which third parties receive telemetry associated with named employees, and for what purpose?
Location Tracking Can Outlast the Shift
The same investigation found that three of the nine platforms offered features capable of tracking a worker’s precise location, including in circumstances where an app runs in the background or the worker may be off the clock. Three apps could also require access to motion-sensor data, such as accelerometer or gyroscope readings, as part of clock-in functionality.
Those features may have legitimate operational uses for delivery, field-service, health-care, and logistics organizations. A dispatcher needs to know where a vehicle is; a lone-worker safety system may need location data; a site supervisor may need evidence that a guard reached a required checkpoint. The problem begins when data retention, access rules, and off-hours behavior are left undefined.
A company that collects location only to confirm an active shift should be able to state, in writing, when tracking begins, when it ends, who can access historical routes, how long the records are retained, and whether data is exported to another provider. If it cannot answer those questions, employees cannot meaningfully distinguish a work tool from a persistent tracking tool.
The AP’s reporting reflects that lack of visibility. Experts told the outlet that workers often have difficulty learning which monitoring capabilities their employer enabled, especially when tracking is built into products used for normal communication or office work.
Microsoft 365 Can Produce Employee-Level Records — If Administrators Enable Them
Microsoft 365 itself includes administration, compliance, audit, and usage-reporting functions that can expose activity at a user level. That is not hidden functionality: Microsoft documents it. What is frequently unclear to employees is whether their own tenant has enabled those capabilities, which roles can view the records, and whether reporting data is shown in identifiable form.
Microsoft 365 usage reports cover activity across services including Exchange, OneDrive, SharePoint, Teams, and Microsoft 365 Apps. Microsoft hides user, group, and site names in many usage reports by default, but a Global Administrator can change the organization-wide setting to display identifiable information. Microsoft says that change is recorded in the Purview audit log.
That default is a privacy control, not an absolute barrier. It means the data can be concealed in a report until an administrator elects to reveal it. Organizations should avoid describing the default as proof that managers cannot see individual activity, because access depends on configuration, assigned roles, and the specific reporting or investigation tool being used.
Microsoft Purview Communication Compliance is a separate example. It can apply policies to Teams channels, private channels, one-to-one chats, and group chats to detect material such as harassment, threats, adult content, or the sharing of sensitive information. Microsoft says usernames are pseudonymized by default within the tool and that access is role-based and audited. Still, the service exists so authorized reviewers can investigate alerts involving organizational communications.
That is a legitimate compliance function in regulated businesses and organizations handling sensitive data. It should not be repurposed casually into a proxy productivity score. Teams message volume, meeting participation, file edits, and presence signals are poor substitutes for evaluating work that depends on research, customer care, design, systems administration, incident response, or long, uninterrupted problem-solving.
The pharmacist featured in the AP report described being measured by call and appointment duration while serving patients with chronic conditions and language-access needs. Her account captures the central managerial risk: a metric can be accurate and still be a bad measure of performance. A short appointment is easy to count; it does not necessarily represent better care.
What Employees Can Ask Without Guessing
Workers should assume that activity performed on an employer-issued Windows PC, work phone, corporate network, or company account may be logged. They should not assume that every available monitoring feature is active. The useful response is to request specific information rather than asking the vague question, “Are you monitoring me?”
A written request to HR, IT, security, privacy, or a manager can ask for the organization’s employee-monitoring notice, acceptable-use policy, endpoint-management policy, data-retention schedule, and the names of monitoring or timekeeping vendors. It can also ask whether the organization collects or reviews:
- Usage-report data from Microsoft 365, Teams, OneDrive, SharePoint, Exchange, or endpoint-management systems.
- Teams chats, meeting transcripts, email, browser history, keystrokes, screenshots, webcam images, or microphone recordings.
- GPS, Wi-Fi, Bluetooth, vehicle, badge, motion-sensor, or mobile-device location data.
- Productivity scores, task-completion targets, AI-generated risk flags, or automated rankings used in performance reviews.
- Data shared with analytics, advertising, data-broker, identity, or other external providers.
The goal is not to demand unrestricted access to security controls or compromise an employer’s ability to investigate fraud, data theft, harassment, or attacks. It is to establish the scope, purpose, recipients, and retention period of data that may later be used in a disciplinary, promotion, scheduling, or termination decision.
Employees should also keep personal activity off work devices and company accounts. That includes medical discussions, family matters, personal cloud storage, private browsing, and personal password-manager vaults. “Private” browsing can limit local browser history, but it does not make activity invisible to an employer-controlled device, network, security agent, or web proxy.
The System Administrator’s Obligation Is Clearer Than “We Can”
For sysadmins and Microsoft 365 administrators, the AP report should be read as a governance warning. Technical capability alone is not a sufficient reason to enable user-level reporting, broad communication review, location collection, or a third-party monitoring agent.
Organizations need a defined purpose for every collection mechanism, least-privilege access to reports, a retention limit, a documented approval path for investigations, and a process for challenging false or context-free conclusions. If employee identities are not necessary for a routine adoption report, keep them concealed. If a compliance policy needs to inspect messages, assign narrowly scoped reviewers rather than granting broad administrative access.
The investigation also calls for vendor review beyond the dashboard. Administrators should test network traffic where contract terms permit it, inventory embedded trackers and software development kits, and require vendors to identify every subprocesser and data recipient. A product’s privacy policy is evidence of what it promises, not proof of what its applications transmit.
The immediate consequence of workplace surveillance is not merely that employees may feel watched. It is that data gathered for attendance, security, scheduling, or collaboration can be reused to make judgments far beyond its original purpose. On a Windows PC and in Microsoft 365, the responsible answer is not pretending those records do not exist; it is making their collection, access, and limits visible before they become evidence against someone.