- In the Modern Workplace Experience (MWE), there is no genuine technical encryption at folder level.
- Folders control access: they determine who is allowed to view and open files.
- New files automatically inherit the permissions of the folder.
- The actual encryption takes place at document level, usually by means of labels or policies.
- The result is functionally folder-based, because access and protection work together seamlessly.
- If a file is shared or copied, the protection remains in place provided that document encryption is enabled
Folder-based encryption in the Modern Workplace Experience
Many people talk about ‘folder-based encryption’, but technically speaking, that is only half the story. What is crucial is the interplay between folder permissions and document-level encryption. It is precisely this principle that ensures secure yet user-friendly data protection in practice.
The Modern Workplace Experience (MWE) is a suite of tools that enables Dinotronic customers to manage their Microsoft 365 environment independently and securely, from structured document storage and encryption to audit-proof archiving.
What does ‘folder-based encryption’ mean in the MWE
At first glance, the term ‘folder-based encryption’ sounds as though an entire folder is technically encrypted, much like a safe that can only be opened with the correct key. In the Modern Workplace Experience, however, the protection mechanism works differently.
The focus here is not on the folder itself as the object of encryption, but on the interplay between access control and document protection. This interplay ensures that content is accessible only to authorised users, even when files are shared or moved.
This is an important distinction: the folder is primarily used for organisation and access control, whilst the actual protection of the content lies with the file itself.
How does the mechanism actually work in the Modern Workplace Experience?
1. Folders control access
The first and most important component is folder permissions. These define who can view files and who is authorised to access them.
In practical terms, this means:
- Folders determine which individuals or groups are granted access
- Within this structure, files are made available in a controlled manner
- New files created or saved in this folder will automatically inherit these permissions
The folder is therefore not an encryption unit in the technical sense. Rather, it acts as the control mechanism for access and encryption. This allows the question ‘Who is authorised to access it?’ to be answered clearly, and this is precisely what constitutes a key security factor in modern collaborative environments.
2. Combining this with document-level encryption
To ensure that access control translates into genuine information protection, a second component is required: encryption at document level.
The process typically goes like this:
- A file is created in a specified folder
- The file automatically inherits the permissions of the folder
- The defined policy assigns a label to the file
- This enables encryption at document level
It is only at this stage that the content is actually protected. The file is then not only stored correctly from an organisational point of view, but is also technically secured.
This has one key advantage: the protection does not just remain in the folder, but travels with the file.
3. Why the result is nevertheless ‘functionally folder-based’
Even though, technically speaking, the encryption is not applied directly to the folder, in practice it functions as if it were folder-based.
After all, the roles are clearly defined. The folder controls access, and encryption protects the content
This separation is particularly useful because it combines user-friendliness with security. Users work within a familiar folder structure, whilst the security mechanisms operate in the background.
The result is a security model that is easy to explain in practice. The folder determines who is allowed access to the workspace. The document ensures that its contents remain protected even when it leaves the workspace.
4. What happens when you open a file
Another important point is how to proceed when opening protected files.
For a document to be legible, certain conditions must be met:
- The user needs a valid account
- The user must have the appropriate authorisation
- Only once these conditions have been met will the file be decrypted or made readable
This provides an additional layer of protection. Even if a file were to fall into the wrong hands, it would remain inaccessible without valid identification and authorisation.
This is a major advantage, particularly in modern, hybrid working environments: security is enforced not only at the storage location, but directly when the document is accessed.
5. How files behave when shared
This model becomes particularly relevant when files are shared, copied or forwarded by email.
This is where the strength of document encryption really comes into its own. The file remains encrypted, so access remains restricted, and the permissions apply not only within the original folder but also after the file has been shared
This is the key difference compared to access protection at the storage location level alone. Whilst traditional access controls often apply only within a single system or directory, document encryption protects the content beyond the storage location. For businesses, this means greater control over sensitive information – even when files are in transit.

Discover the potential now
Would you like to find out how you can implement encryption in your Modern Workplace in practice?
👉 Book a no-obligation consultation now and receive a personalised assessment as well as concrete implementation strategies for your organisation.
Conclusion
Strictly speaking, “folder-based encryption” in the Modern Workplace Experience is not a purely technical feature at folder level. Rather, it is an effective combination of folder permissions and document encryption.
The folder determines who is authorised to access it.
Encryption at document level ensures that content remains protected, even beyond its original storage location.
This is precisely why the term is still useful in practice: not because the folder itself is encrypted, but because users experience the protection as if it were tied to the folder.
This creates a security model that is both effective and suitable for everyday use, making it ideal for modern working environments.
Our expert
Nico Schwerzmann
Our Information Protection Expert
Nico supports companies in implementing modern workplace concepts, with a focus on security, governance and user-friendliness. His main focus is on designing information protection in such a way that it not only works from a technical perspective, but is also accepted and used effectively in day-to-day working life.
