Forgot your password?
typodupeerror
Windows IT

Microsoft Responds to Outcry After Quietly Installing Beta 'Photos' App on Enterprise Machines (windowslatest.com) 72

Microsoft's cloud storage app OneDrive got a new Photos app in the worst possible way, reports the blog Neowin . "The app is reportedly showing up even on Windows 11 Enterprise machines, despite apparently being a beta application aimed at consumer functionality." One admin questioned why a beta app was appearing on an Enterprise SKU in the first place, while another described the situation as yet another consumer-oriented feature being forced onto corporate PCs. Things get even more frustrating for IT departments because there does not appear to be a straightforward Microsoft-provided way to disable the app... Enterprise administrators generally need to know what is being installed on their managed devices, particularly when a software is labeled as beta. Quietly adding another application and leaving admins to clean it up themselves is therefore unlikely to win Microsoft many fans.
But there's another problem, according to the blog Windows Latest. "OneDrive Photos automatically scans your system storage for photos," and apparently "doesn't need a Microsoft account to work, as it can also detect your local files." There's also a People section that groups similar faces in your photos. Microsoft asks for permission before turning it on and explicitly warns that facial data could be considered biometric data in some regions. The company says only you can see the grouped faces, that the data isn't shared with third parties, and that you can delete it by disabling the feature.
In a statement to Neowin, Microsoft admitted this new photos "experience" they're "incubating" had gone "more broadly than it should have," and then promised that "We're fixing that." The spokesperson also said the Windows Photos app will "always give you the option of local and cloud photos" and, also a choice of whether or not to use it OneDrive."

But there's another "awkward catch," notes the blog Digital Trends. "Users currently can't uninstall OneDrive Photos without removing the main OneDrive app too." Because OneDrive Photos is tied to the main OneDrive sync client, Windows 11 doesn't currently offer a separate uninstall option. The only straightforward way to get rid of OneDrive Photos right now is to uninstall OneDrive itself... Removing the main client can also affect its File Explorer integration and shortcuts...

Microsoft says this will change. The company is working on controls that will let users remove OneDrive Photos separately from the main OneDrive app. On enterprise PCs managed through Intune, Microsoft says the app will automatically disappear where it isn't supported.

Microsoft Responds to Outcry After Quietly Installing Beta 'Photos' App on Enterprise Machines

Comments Filter:
  • Ouch (Score:5, Insightful)

    by Anonymous Brave Guy ( 457657 ) on Monday August 10, 2026 @12:55AM (#66281304)

    It was obnoxious enough when Microsoft started pushing this kind of unwanted "feature" on home users, then small businesses and professionals on Pro editions. There are real legal and regulatory concerns over this kind of change that businesses have to take seriously. If they've screwed up so badly that even their large corporate customers have been hit by the same thing and there isn't even a good way to undo the damage at the moment, this could lead to meaningful lawsuits from their customers and/or interventions by regulators.

    • Re: (Score:2, Informative)

      by thegarbz ( 1787294 )

      If they've screwed up so badly that even their large corporate customers have been hit by the same thing and there isn't even a good way to undo the damage at the moment, this could lead to meaningful lawsuits from their customers and/or interventions by regulators.

      You always shoot first and ask questions later? OneDrive photos works only on personal Microsoft accounts. The accidental rollout for enterprise users has done nothing more than cause OneDrive to display a sync error in the task bar, and flash an error message if someone opens the photos app.

      So no, there's no legal or regulatory concerns over this in the slightest. There's some annoyance, but let's face it if anyone tried to sue Microsoft for being annoyed about having to do extra work due to MS fuckups, th

      • Re:Ouch (Score:5, Insightful)

        by ufgrat ( 6245202 ) on Monday August 10, 2026 @07:18AM (#66281576)

        I work in the medical profession. Downloading images that contain patient health information is supposed to be controlled, but that doesn't mean it always is.

        And it's not the "microsoft account" you have to worry about, it's someone logging into OneDrive with their personal account, which can be a separate authentication.

        There are mitigation policies that can be deployed, but you kind of have to know to enable them. By default, this is a massive potential HIPAA violation.

        • And it's not the "microsoft account" you have to worry about, it's someone logging into OneDrive with their personal account, which can be a separate authentication.

          You can't log OneDrive into a personal account using the app if you are logged into your PC with a work or school account, the windows login and the app are interlinked. You can only use OneDrive online to do that, so yeah again not relevant.

          • by ufgrat ( 6245202 )

            Only if the GPO policy is in place. By default, you can do personal authentication against OneDrive, even on a domain joined desktop.

      • Re: Ouch (Score:4, Interesting)

        by topham ( 32406 ) on Monday August 10, 2026 @10:59AM (#66281900) Homepage

        "The accidental rollout for enterprise users has done nothing more than cause OneDrive to display a sync error in the task bar, and flash an error message if someone opens the photos app."

        If you think that none of that is a big deal you haven't worked in an actual restricted environment.

        This will potentially require servers to be wiped and rebuilt in some environments. Even if everything is configured correctly and this update did not make it to restricted servers, they will likely have to be specifically audited to prove that to the powers that be.

        Having an error message pop up on users machines also means dozens, to hundreds or thousands of calls to service desks to address the issue. Nothing like getting top executives to file a service ticket and having to reprioritize your day because of it over something as stupid as the, and yet that's what happens.

        • If you even have onedrive and direct internet connection in a restricted environment you are in for a number of problems.

        • If you think that none of that is a big deal you haven't worked in an actual restricted environment.

          No I didn't say it's not a big deal, I said there's no legal clash here. It's as big of a deal as any other botched update, but it's not exfiltrating data like the OP seems to suggest.

      • You always shoot first and ask questions later?

        No, I read the details explicitly quoted at the start of the discussion and responded to them.

        Are you saying that this episode has not in fact resulted in (a) unplanned software being installed on end devices that will (b) automatically read data that is stored on those devices without the proper approvals? Either of those things alone can easily become a compliance problem if you operate in a regulated environment, whether or not things ultimately go any further on this occasion.

        • b) is incorrect. It does not automatically read data from any business / school account - i.e. the accounts that are used due to regulatory restrictions. Sure there may be some people using personal Windows installations for the small business, but then that's a failing on their behalf, probably the same kind of business who already loads everything to OneDrive as their ownly backup stratergy.

          Any business which does care has this as only a minor annoyance.

          • What, specifically, do you mean by "personal Windows installations"?

            Are you suggesting that any business of any size should only ever use Enterprise editions of Windows?

    • The only thing that matters is that they were able to exfiltrate your data again.

  • Fucking Bastards (Score:5, Insightful)

    by r0nc0 ( 566295 ) on Monday August 10, 2026 @01:00AM (#66281310)
    Searching for all local images, computing facial metrics and uploading them to Microsoft. Holy shit what a bunch of assholes.
  • by Casandro ( 751346 ) on Monday August 10, 2026 @01:52AM (#66281334)

    ... that if you get software without source code and it has an auto-update feature you cannot control... maybe you are not the person who owns those computers.

    • by TuringTest ( 533084 ) on Monday August 10, 2026 @03:56AM (#66281428) Journal

      ... that if you get software without source code and it has an auto-update feature you cannot control... maybe you are not the person who owns those computers.

      This was (and still is) the #1 reason why open source software became the basis for the internet and corporate world. Being free of charge gained home users and small companies, but what made it grow was corporate adoption pouring money into it to make it viable.

      People forgetting history makes them repeat all again, I guess.

    • by thegarbz ( 1787294 ) on Monday August 10, 2026 @04:11AM (#66281452)

      Implying that having the source code gives you ownership?

      The number of people who actually compile their OS from source is so close to zero as to be meaningless in the world.
      Additionally users fall into two categories:
      1. Those who do auto-update, or apply updates quickly.
      2. Idiots who think they own their computer whereas it probably belongs to someone in Russia or North Korea.

      Precisely no one in the world audits all code going into their computer via updates, and given that a rollout here happened, was immediately uncovered and then hit the news, there's no reason to believe having source code available would in any way have sped up detecting the problem
      And we know quite well not auto-updating leads to more active zero days exploited in the wild, so that's not something you should be striving for.

      So... is your computer owned by someone in Redmond, Cupertino, London, Moscow, or Pyongyang? It most certainly isn't owned by you.

      • You don't need a full audit to find out why the software is doing something weird, nor all companies need to do it.

        Some companies care about their mission-critical software so they will be monitoring it carefully. If some very popular package is doing malicious things, the chances that it will be caught are quite high. And if the software is FLOSS it's way easier for the company to fix it themselves, release the fix upstream and warn the world about the fishy nature of the provider. So no, I don't believe a

        • Some companies care about their mission-critical software so they will be monitoring it carefully.

          And they have been hit by this. The companies that care are also the ones that don't delay for long periods of time to do full audits.

          Yes in this case it was something obviously stupid that could have been quickly caught by an update audit. But in many cases bugs or unintended effects from updates aren't shallow. That applies to closed source, it applies to open source. One system vs the other doesn't make you immune.

      • Well but for normal distributions there are two big advantages compared to commercial updates.

        1. You can turn it off at any time
        2. It's designed to make it _very_ hard to specifically provide special update for a special target, since the process is transparent, and mirrors are something that's encouraged.

        Particularly part 2 is relevant in an age where an US-president could just force a company to send a special version of program X to person Y.

        • by markdavis ( 642305 ) on Monday August 10, 2026 @07:29AM (#66281580)

          And, generally, there is no motivation for a community-driven Linux distro to force crap on their users.

          Plus there is no lock-in with Linux (unless you make it that way, yourself). Some people like to complain about "too many Linux distros" who are used to having a single vendor they cannot escape (Microsoft). Yet with Linux, if you don't like the direction or actions of one distro, you can switch to another.

          We know more businesses are switching to Linux. But I predict, over time, more of those are also going to choose something like Debian or Mint over RHEL or Ubuntu.

          • And, generally, there is no motivation for a community-driven Linux distro to force crap on their users.

            There's no such thing as a "community-driven" Linux distro. Distros are driven by maintainers, corporations or upstream. A simple example of this is the endless fiascos we've had with systemd, or flatpacks, or whatever the community disagreement of the day is.

            The second half of the post is correct though. The lack of lock-in does make it possible to find a maintainer/corporation driven distro that does suit your use case and values.

          • And, generally, there is no motivation for a community-driven Linux distro to force crap on their users.

            Then explain SystemD...

            • >"Then explain SystemD...

              You know, when I wrote the post, I was thinking about "well, there is systemd..."

      • by MeNeXT ( 200840 ) on Monday August 10, 2026 @10:11AM (#66281790)

        You make it sound as if MS and the open source community work in the same way. In the last 40 years I have never experienced a open source OS like Linux or FreeBSD install software that I didn't request. If they had, all the tools to suppress/remove it are available.

        Precisely no one in the world audits all code going into their computer via updates

        It guess then this would surprise you that many audit the code or packages that they install. I will guarantee you that the packages installed on my servers are all approved by me. But that's me and I would say diligent sysadmins.

        • In the last 40 years I have never experienced a open source OS like Linux or FreeBSD install software that I didn't request.

          You don't automatically apply security updates? If you're talking about explicit new software, then congrats you are working with people who didn't push that to you, but you are very much NOT immune from it, you're just trusting whomever is offering you security updates that they don't pull stupid MS shit.

          • by MeNeXT ( 200840 )

            No. Nothing is automatically applied.

            The reason MS can get away with this is because people have locked themselves in a proprietary system which they refuse to migrate from.

            Change your attitude. Demand open standards. You will be surprised how stable computing can become.

        • You make it sound as if MS and the open source community work in the same way. In the last 40 years I have never experienced a open source OS like Linux or FreeBSD install software that I didn't request. If they had, all the tools to suppress/remove it are available.

          As I just said to someone else using this line of logic: Explain SystemD...

      • by Tarlus ( 1000874 )

        Implying that the code can be fully audited, so any person so inclined can find out exactly what the software is instructing their computer to do with their data (or whom it shares it with).

        • Can is not the same as I. Just because something can be done doesn't mean anyone has the time and resources to do so. Just look at open source encryption. It took close to a year to fully audit single packages, which means precisely no one is auditing entire OSes much less the security updates pushed by them.

    • And people keep telling me I should upgrade to 11.
  • by NotEmmanuelGoldstein ( 6423622 ) on Monday August 10, 2026 @02:12AM (#66281350)
    Customer's data stolen by Microsoft to feed Microsoft's other product, AI. Microsoft wasn't the first but forcing customers into servitude, without monetary compensation, makes this malware.
  • by JakFrost ( 139885 ) on Monday August 10, 2026 @02:15AM (#66281354)

    I've had to uninstall OneDrive more than a dozen times because every time Microsoft office gets updated it pushes that install back onto the machine. Anytime Microsoft releases a new version of a large update to Windows, it pushes that client again. I have to uninstall it and make sure that none of my files have been forcefully moved to the OneDrive before I remove it.

    Now they are doing this to capture your photos and facial profile data to do facial recognition and grouping.

    Microsoft is the right hand man of the surveillance industry. They always have been and they are more so now. Now they're just more incompetent about it.

    • Re: (Score:3, Insightful)

      by thegarbz ( 1787294 )

      I have to uninstall it and make sure that none of my files have been forcefully moved to the OneDrive before I remove it.

      Precisely nothing is forcefully moved to OneDrive unless you've explicitly enabled it to do so (maybe in the past). Even if OneDrive is installed the worst you get to experience is an app that pops up a window asking you if you are going to use it.

      But it is annoying that they push it with Office, however cloud syncing is a core feature of Office so it's not surprising that they do so. It would be the equivalent of shipping word without the spell checker at this point. If you don't like this core feature tha

      • How difficult is it for an operating system update to detect whether or not a service is installed, and if not, then not install it unless it is explicitly requested?

        I find it strange that this simple design philosophy is ignored. When a user installs or updates software, they should be presented with a dialog box with a list of components that can be checked/unchecked for installation, with any dependencies reflected as appropriate. The whole paradigm of "automatic" and "background" updates is absolutely

        • I find it strange that this simple design philosophy is ignored.

          It's Windows.

          For years, Microsoft used revenue as a metric to know if a feature was good or not. This gave them customer feedback, and they could adjust accordingly.

          Around the time of Vista, it stopped working as a metric because everyone had already bought Windows. By that time, corporate motivation had changed, and the motivation of managers was to backstab each other as they climbed the corporate ladder. So they never really came up with another metric to determine if customers liked their product o

      • by drinkypoo ( 153816 ) <drink@hyperlogos.org> on Monday August 10, 2026 @09:53AM (#66281750) Homepage Journal

        Precisely nothing is forcefully moved to OneDrive unless you've explicitly enabled it to do so

        womp womp [microsoft.com]

        It's unclear why you tell so many lies on behalf of Microsoft, but it would be cool if you could stop.

        • It's unclear why you have reading difficulties. OneDrive does not auto enable without user intervention, and your response is to say "womp womp" by linking an article describing changing folder defaults on an *already enabled and active OneDrive*.

          Congrats, you once again showed a lack of grade school English competence. I'm not worried about being called a "liar" by someone so stupid.

    • I was just going to ask about that, because the article summary makes it seem like uninstalling OneDrive is simple/easy, when it's anything but.

      I have my own NAS with a good sync client, I never use OneDrive, yet I gave up uninstalling on my family machines, it always finds a way to pop back like a bad infections disease. These days I'm just happy if it sits there w/o an authenticated user and don't nag to sign-in too often. Sigh!

  • by Arnonyrnous Covvard ( 7286638 ) on Monday August 10, 2026 @02:19AM (#66281362)

    Liking it is optional

  • Congratulations comrade on your Non-Consensual participation in our Microsoft OneDrive Photos Beta integration with Flock facial recognition features, to ensure that our synergy works for the best of what Big Brother has always wanted for everyone!

    - Microsoft All Channels Marketing

  • Removal (Score:5, Insightful)

    by Errol backfiring ( 1280012 ) on Monday August 10, 2026 @06:23AM (#66281520) Journal

    "Users currently can't uninstall OneDrive Photos without removing the main OneDrive app too."

    That is a feature, not a bug.

  • Elephant in the room (Score:5, Informative)

    by rsilvergun ( 571051 ) on Monday August 10, 2026 @09:29AM (#66281722)
    It gobbles up half a gig of RAM. At a time when ram is at a premium that's a big deal. I am sure Microsoft has multiple departments fighting amongst themselves to see who is going to get access to your ever dwindling ram supply.
  • by AcidFnTonic ( 791034 ) on Monday August 10, 2026 @11:27AM (#66281978) Homepage

    To think, I used to be jealous of domains. Windows 2000 era domains were just serious and interesting. As a linux nerd there wasn't really anything as simple to manage a ton of computers. Setting policy on a ton of various things in a central place with roaming and local profiles. LDAP on unix was still not as fun even if more powerful.

    Then here I am today in 2026 thinking they are throwing away the last thing they were good at. Pissing off the enterprise customers is going to make a lot of people unhappy. Now windows management is split between multiple places, different tools, migration utilities, powershell, WSL, etc. It's a joke. I am look at it and just shake my head. It does nothing better these days. Clock is ticking.

  • Oddly enough, the Photos app included a single image depicting the album art for U2's Songs of Innocence.
  • I have OneDrive through Sharepoint, and I don't see any photo app in the Office 365 apps tool. What am I a missing?
  • Seriously, what do you expect? That Windows "Enterprise" is somehow magically managed any better by MS?

  • I personally I am not motivated to switch over (I like my workflow with Windows), but anybody that does, thanks. It will get their attention and it will start to make a difference.

    As much as Microsoft's leadership wants people to think AI and Azure is Microsoft, their brand is Windows. The worse Windows is, the worse their brand is.

  • What is the difference between this and malware?

Don't steal; thou'lt never thus compete successfully in business. Cheat. -- Ambrose Bierce

Working...