I really have never heard of on prem 365 deployments, I think any confidentiality is handled via contracted promises with legal ramifications for breaking. With Azure GovCloud for instance there’s no encryption / user key custody on the one drive side, everything you do is uploaded to Microsoft and they maintain keys, they just hire people who passed a background check to run the infrastructure, US nationals only etc
I really have never heard of on prem 365 deployments, I think any confidentiality is handled via contracted promises with legal ramifications for breaking. With Azure GovCloud for instance there’s no encryption / user key custody on the one drive side, everything you do is uploaded to Microsoft and they maintain keys, they just hire people who passed a background check to run the infrastructure, US nationals only etc