← all articles

What Your Workplace Can See on a Work Laptop

The short answer: more than you think, less than everything

If IT issued the laptop, assume they can see a lot. Modern device management is built from several independent systems that each capture a slice of activity, and those slices overlap more than people expect. None of this requires anyone to be malicious or nosy. It’s just what happens when a company owns the hardware, manages the network, and has a legitimate interest in security and compliance.

The goal here isn’t to make you paranoid about your job. It’s to explain the actual mechanisms, so you can reason about what’s visible instead of guessing.

The root certificate that unlocks encrypted traffic

The single biggest thing people misunderstand is HTTPS. Employees often assume that because a site shows a padlock, their employer can’t see what’s inside the connection. That’s true on your home network. It’s often false on a managed corporate laptop.

Here’s the mechanism: many companies push a root certificate authority (CA) onto managed devices through their MDM profile. Once that root cert is trusted by the device, the corporate proxy or firewall can sit in the middle of your HTTPS connections. It terminates your TLS session, reads the traffic in plaintext, then re-encrypts it before sending it on to the actual website. Your browser shows a valid, secure connection the whole time, because as far as the browser is concerned, it is one, just to the corporate proxy instead of directly to the site.

This is called TLS inspection, and it’s standard in a lot of enterprise environments for malware scanning and data loss prevention. It typically applies to traffic that passes through the corporate network or VPN. If the laptop is on a network that doesn’t route through that proxy, this particular mechanism doesn’t apply, though other things below usually still do.

Endpoint agents watch the machine, not just the network

Separate from anything network-related, most work laptops run an endpoint detection and response (EDR) agent, things like CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint. These run locally on the machine and are designed to catch malware and intrusions, but their visibility extends further than that by necessity.

An EDR agent typically logs process execution (what programs ran), file system events (what was created, moved, or deleted), and network connections initiated from the device. Some configurations include command-line arguments, which means if you ran a script or a terminal command, the string itself may be logged. This isn’t the agent reading your screen, it’s the agent recording system-level events that your operating system already generates, and forwarding a subset of them to a central console for the security team.

Separately, some companies deploy employee monitoring software on top of this, tools like ActivTrak, Teramind, or Hubstaff, which are a different category. These are explicit productivity or insider-threat tools and can include periodic screenshots, active window titles, keystroke counts, and idle time tracking. Whether a given laptop has this installed depends entirely on company policy. It’s a different product from EDR and serves a different purpose, so the two shouldn’t be assumed to be the same thing.

Your browser is probably managed, not just installed

If the browser was installed and configured by IT (Chrome Enterprise, Edge with Group Policy, or Firefox with an enterprise policy file), it can be centrally managed in ways that go beyond simple settings. Enterprise browser policies can disable incognito mode, block or force-install specific extensions, and in some configurations, sync browsing history to an admin console the same way personal Chrome sync works but pointed at the company’s management tier instead of your personal Google account.

This is a policy-and-configuration mechanism, not surveillance software hiding on the device. It’s the same sync and reporting infrastructure Google or Microsoft already built for enterprise fleet management, just pointed at IT’s dashboard instead of turned off. Whether history sync is enabled depends on how the organization configured the browser policy, so it varies by employer.

Network logs exist even without content inspection

Even without TLS inspection, connecting to a corporate Wi-Fi network or VPN generates metadata that IT can see by default, because it’s a normal side effect of how networking and DNS work.

Every domain your laptop resolves goes through a DNS query, and if that query goes through a company-controlled DNS server (common on corporate networks and required by most VPN configurations), the domain names you visit are logged there regardless of whether the content is encrypted. Separately, the TLS handshake itself includes a field called Server Name Indication (SNI), which states which domain you’re connecting to in plaintext, before encryption kicks in, so a network firewall can see the destination domain even without decrypting anything. Between DNS logs and SNI visibility, a fairly complete list of domains visited is available at the network level with no need to inspect content at all.

This is why “I didn’t get flagged so nobody’s watching” isn’t a safe assumption. Nobody has to be watching in real time for the log to exist. It sits there, searchable, if anyone ever needs to look.

What usually stays outside the picture

It’s worth being specific about the limits, because absolutist claims in either direction (“they see everything” or “they can’t see anything if you’re careful”) are both wrong.

Traffic that never touches the corporate network or VPN, personal browsing on a personal phone using cellular data, for instance, isn’t visible to any of the mechanisms above, because none of them have a vantage point on that connection. A company laptop connected to your home Wi-Fi without the VPN active also usually bypasses the network-level logging and TLS inspection described earlier, though the EDR agent is local software and typically still reports back over the internet regardless of which network you’re on, since its job is independent of network location.

Personal accounts logged in through a personal browser profile that IT didn’t configure are also generally outside browser-policy sync, though they can still show up in EDR process and network logs simply as “a browser process made a connection,” without necessarily identifying content.

None of this adds up to a way to be invisible on a company asset. It’s closer to understanding which layer a given activity passes through, and which layer’s owner can see it.

The practical takeaway

Treat a company-issued laptop as company-monitored infrastructure, because structurally, that’s what it is: hardware they own, running software they configured, often routed through a network they control. That’s a reasonable default whether or not any individual policy is aggressively enforced, because the visibility comes from the architecture, not from someone deciding to snoop.

The useful move isn’t finding a workaround. It’s separating contexts: personal accounts, personal banking, and anything sensitive on personal devices over your own connection, and work-related activity on the work laptop where it’s expected to be visible anyway. It’s just matching your behavior to which system is actually watching.

If you want to understand the mechanisms behind the tools your employer, your ISP, or advertisers use, and how each one actually works under the hood, that’s what we cover on the site home page.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →