Does DPAPI Protect Clipboard History From Other Users?
The short useful answer: another Windows user who is not in this session should not see this user’s Win+V list. That isolation comes from profiles and the clipboard service running as that user, not from a consumer-facing “DPAPI checkbox.”
The short precise answer: Microsoft Support does not document clipboard history as a DPAPI feature. DPAPI (CryptProtectData) is a real Windows API that binds ciphertext to a user or to a machine. Many user secrets use it. Independent forensic write-ups have found clipboard-history files under the user profile. Combining those facts into “DPAPI makes Win+V safe from everyone” is a leap this page will not take.
What Microsoft does document about history
- History is off until enabled (Win+V or Settings > System > Clipboard).
- 25 items, 4 MB, text / HTML / bitmap.
- Unpinned items clear on restart; pins persist.
- Optional sync is account-tied text.
- Clear clipboard data clears unpinned items on the device and, when used, the cloud copy.
Microsoft does not, in the Support article, say “history is encrypted with DPAPI” or name a file path. Using the clipboard is silent on both.
Treat everything below the profile folder as implementation detail that can change.
What forensic write-ups have observed
Public DFIR notes (for example ThinkDFIR’s 2018 look at the then-new history feature) observed a folder created at:
C:\Users\<user>\AppData\Local\Microsoft\Windows\Clipboard
with HistoryData and Pinned subfolders. That matches a per-user store. It is not an official API contract. Do not write cleanup scripts that assume those names will exist forever.
A per-user folder already answers the household question better than cryptography: User B is not supposed to read User A’s AppData. NTFS ACLs and separate tokens do that work every day.
What DPAPI actually is
Microsoft Learn, CryptProtectData:
- Encryption uses a session key derived from the user’s logon credentials.
- Typically only a user with matching credentials can decrypt, usually on the same computer.
- A user with a roaming profile may decrypt on another computer.
- Flag CRYPTPROTECT_LOCAL_MACHINE binds data to the machine. Then any user on that computer can decrypt.
Master keys live under the user’s profile (%APPDATA%\Microsoft\Protect\<SID>\ is the documented DPAPI key location in Microsoft and security literature). DPAPI does not prompt on every call; the logon session unlocks the keys.
Consequences that matter for clipboard talk:
| Situation | Does “user-bound DPAPI” help? |
|---|---|
| Sibling signed into their own Windows account | They should not open this profile’s files. ACLs first; DPAPI would be extra if history files are wrapped |
| Sibling at an unlocked session | No. They press Win+V as the logged-on user. Keys are unlocked |
| Malware in this session | No. It calls the same APIs the user can call |
| Attacker who stole the password and logged on | No. They *are* the user |
| Offline disk in another PC, BitLocker off | Profile copy may be readable; DPAPI blobs still need the user’s secrets or offline attacks. This is specialist territory, not a consumer guarantee |
CRYPTPROTECT_LOCAL_MACHINE | No user isolation. Anyone on the box can decrypt that blob |
Can Other Apps Read Everything You Copy? is about the live clipboard in the session. DPAPI never enters that path. The live clipboard is RAM for the current desktop.
So what actually protects history from “other users”?
1. Separate Windows accounts. This is the control. Fast user switching keeps two profiles. Win+V in account B does not show account A’s list.
2. Locking the session. Win+L. DPAPI is irrelevant if the desktop is open.
3. Restart. Unpinned items go away. Pins do not. Clipboard History Cleared After Restart? That Is Normal.
4. BitLocker. Full-volume encryption protects the disk at rest when the PC is off and the key is not sitting in the bag. It is not DPAPI and it is not Win+V.
5. Not enabling sync. Cloud text is outside DPAPI-on-this-disk. Another person with the Microsoft account password has a different door. How to Disable Windows Clipboard Cloud Sync.
6. Not sharing the Microsoft account. Shared Microsoft Accounts and Clipboard Sync Leaks.
What DPAPI does not stop
- Phone Link replacing the live clipboard. Phone Link Clipboard Access: Privacy Checklist.
- Suggested actions reading a number. Turning Off Suggested Actions for Privacy.
- A lab that uses one
STUDENTlogin. Student Lab PCs and Leftover Clipboard Data. - An administrator with backup or forensic access. “Other users” in a home sense is not “other users” in an enterprise IR sense.
- Third-party databases (Ditto, CopyQ) that store plaintext or their own encryption. Ask those apps. Do not assume DPAPI wraps them.
Does a Local Clipboard App Need Encryption at Rest?.
Practical checks
To confirm isolation on a shared family PC:
- Enable history in account A. Copy
alpha-from-A. - Sign out. Sign into account B. Win+V should not show
alpha-from-A. - Sign back into A. The string may still be there if it was pinned or if the PC did not restart and history stayed on.
That test does not prove DPAPI. It proves profile isolation, which is what households need.
To confirm the live clipboard is the weaker boundary: stay in account A, leave the session unlocked, and let anyone press Win+V. Encryption of files on disk cannot help.
Enterprise wording
If a security questionnaire asks “is clipboard history encrypted at rest with DPAPI?” the accurate reply is:
Microsoft documents clipboard history as a per-user feature. Support does not specify DPAPI. History files have been observed under the user’s AppData. User-bound DPAPI is how Windows protects many profile secrets, but it does not protect an unlocked session and does not replace BitLocker, account isolation, or disabling cloud text sync.
Do not tick “encrypted, therefore shared-PC safe.”
Roaming profiles and the machine flag
CryptProtectData remarks that a user with a roaming profile may decrypt on another computer. That is a domain-join story. A home Microsoft account that syncs some Windows settings is not automatically a roaming profile in the AD sense. Do not assume clipboard-history files roam with a consumer account. Official consumer sync of clipboard text is the Settings toggle, which is a cloud path, not DPAPI.
The CRYPTPROTECT_LOCAL_MACHINE flag is the opposite of user isolation: any user on that PC can decrypt. There is no public Microsoft statement that clipboard history uses that flag. If a third-party app’s own database uses machine-scope DPAPI, it is not isolated between siblings. Read that app’s docs; do not guess.
Optional local tools
A third-party shelf that writes JSON or SQLite in AppData is only as isolated as that file’s ACLs and encryption. Edge-Drop is a local optional shelf for drag-out; it does not add DPAPI theater and should not be described as doing so.
Related reading
- Privacy Settings Checklist for Any Clipboard Manager
- When Cloud Clipboard Sync Is Actually Fine
- Does Windows Clipboard Sync Upload What You Copy?
- Why You Cannot Drag Old Clipboard Files Into Explorer
Sources
- CryptProtectData (Microsoft Learn) — user versus machine binding, roaming-profile note.
- Using the clipboard (Microsoft Support) — official history behavior; no DPAPI claim.
- How to use clipboard history in Windows 11 (Microsoft) — per-account sync, not disk cryptography.
- ThinkDFIR: Clippy History (2018) — observed AppData\Local\Microsoft\Windows\Clipboard layout; implementation detail, not a Support contract.
- BitLocker overview (Microsoft) — volume encryption, a different control than DPAPI.
Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.
GitHub · LinkedInCopy. Stack. Drop.
Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.
Download for Windows Get from Microsoft Store
How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support
Free · Lightweight · Privacy First