What it means
OneDrive can notify eligible users when file changes resemble ransomware and offer a guided restore. That identifies a cloud-file problem and a possible recovery point. It does not remove the malware from each connected computer. If a device remains infected and continues syncing, it may upload encrypted versions again after a successful restore. Microsoft's workflow therefore places device cleanup before cloud restoration.
A real-world example
A desktop encrypts files in its synced OneDrive folder overnight. The owner restores cloud files from yesterday while the desktop stays online. New encrypted copies appear again because the desktop source was never isolated or cleaned.
What to do
Confirm the alert in OneDrive itself, isolate affected devices, clean or reset them using trusted instructions, secure account access if needed and then restore from a known-good point. Verify representative files and watch sync activity.
The distinction that matters
The cloud can be damaged by unauthorized account access without malware on a PC, and an infected PC can damage files without the cloud account being taken over. Investigate both paths. Detection and recovery windows depend on the user's plan; independent backups remain necessary. Preserve incident timestamps and avoid reattaching an unclean machine simply because restored documents look normal in a browser. A clean cloud copy does not disinfect an endpoint.
Microsoft ransomware recovery workflow