No, Microsoft 365 is not the same as a traditional full backup solution. Microsoft ensures the availability of its platform and offers features such as retention, recycle bins, and versioning, but that does not automatically mean you can always independently restore a full copy of all your Microsoft 365 data.
Microsoft ensures that Microsoft 365 as a cloud service remains reliable and available. That is not the same as an independent backup of your Exchange, OneDrive, SharePoint, and Teams data.
What does Microsoft protect itself?
Microsoft builds a lot of redundancy and availability into its cloud platform.
Think for example of:
- replication of data within the Microsoft infrastructure;
- protection against hardware failures;
- service continuity;
- platform recovery;
- built-in recovery options within certain Microsoft 365 services.
But platform availability is not the same as a backup strategy for your organisation.
Which recovery options are standard?
Microsoft 365 includes various built-in mechanisms that are very useful in many situations.
For example:
- recycle bins in SharePoint and OneDrive;
- version history of files;
- Deleted Items and Recoverable Items in Exchange;
- retention policies and retention labels, if correctly configured;
- other recovery and compliance functions depending on licence and configuration.
But they are not automatically the same as a separate, independent backup copy.
Why is versioning not a full backup?
Version history helps when a file was incorrectly modified or overwritten.
You can often revert to an older version.
That is valuable, but it has a different purpose than backup.
saves changes within the primary platform.
Backup
saves a recoverable copy that is managed according to a separate backup policy.
A backup strategy must determine, among other things:
- what is backed up;
- how often;
- for how long;
- which recovery points are available;
- how quickly data can be restored;
- who is authorised to perform recovery.
Why is the recycle bin not a backup?
The recycle bin is designed for recovery after deletion.
But retention periods and product rules also apply there.
Moreover, a recycle bin only helps when the deleted data still falls within the recoverable period and has not been lost in a way outside that mechanism.
And what about retention?
Microsoft Purview retention can be very powerful.
For example, it allows you to set rules to keep certain information for a specific period, even when a user deletes it.
This is especially important for:
- compliance;
- legal hold;
- records management;
- internal retention policies.
Retention determines how long information must be kept. Backup is about recoverability after loss, deletion, corruption, or other incidents.
What if a user accidentally deletes something?
Then the built-in Microsoft 365 recovery options are often the first place to look.
For example:
- recycle bin;
- second-stage recycle bin in SharePoint;
- version history;
- Recoverable Items;
- retention, if configured.
The question is mainly what happens when the standard recovery mechanism is not sufficient.
What if the error is only discovered months later?
Then it becomes much more important to know which retention and backup periods your organisation applies.
Suppose someone deletes important files today and no one notices.
Only months later, during an audit or client request, it becomes clear that the information was still needed.
What if an employee deletes something deliberately?
Not all data loss is accidental.
Think for example of:
- a departing employee deleting files;
- a malicious insider;
- a compromised account;
- a script or application that modifies or deletes large amounts of data.
Then you do not want to be fully dependent on the same primary environment where the incident occurred.
And ransomware?
Cloud data can also be affected when a compromised account or synchronised device modifies, encrypts, or deletes large amounts of files.
OneDrive and SharePoint offer various recovery mechanisms, but ransomware is precisely the kind of scenario where you want to know in advance:
- which recovery points are available;
- how long they remain available;
- how quickly large amounts of data can be restored;
- whether you have an independent recovery path.
Security tries to prevent an incident. Backup helps when prevention was not sufficient.
Microsoft now offers Microsoft 365 Backup, right?
Yes.
Microsoft now has a specific service available for Microsoft 365 backup.
It focuses on fast backup and recovery of certain Microsoft 365 workloads and is a different service from the usual built-in version history, recycle bins, and retention.
Microsoft 365 itself contains recovery and retention functions, while backup can be set up as a separate service.
Does my organisation always need a separate backup?
For business data, we recommend making this assessment consciously.
The right question is not:
but:
That depends on:
- how critical your data is;
- which Microsoft 365 services you use;
- how long you need to be able to restore data;
- how quickly recovery must happen;
- which compliance requirements apply;
- how big the impact of data loss is.
Which Microsoft 365 data should you consider?
In a backup strategy, you look at least at the workloads your organisation truly relies on.
For example:
- Exchange Online mailboxes;
- OneDrive;
- SharePoint Online;
- Teams data that relies on SharePoint and other Microsoft 365 services;
- other critical cloud data depending on the chosen backup solution.
Therefore, you need to know what is actually being backed up.
Backup must also be actually recoverable
Simply stating that "a backup is running" is insufficient.
A professional backup policy also determines:
- how backups are monitored;
- what happens in case of errors;
- who is authorised to perform recovery;
- which retention applies;
- how restore procedures work;
- whether recovery is periodically tested.
Backup must also be well secured
A backup contains a copy of often very sensitive business data.
Therefore, the backup environment must also be protected.
Think of:
- strong authentication;
- MFA;
- least privilege;
- limited administrator rights;
- logging and auditing;
- clear recovery rights;
- protection against unauthorised deletion.
And GDPR?
A backup often contains personal data.
Therefore, you must also take into account:
- purpose limitation;
- access restriction;
- retention periods;
- security of the backup;
- agreements with suppliers and processors;
- deletion and retention policy.
Backup retention must also be consciously determined.
What is the biggest misconception?
That is an overly simplistic view.
Microsoft provides an extremely robust cloud platform with various built-in recovery mechanisms. But your organisation remains responsible for deciding which data it must be able to restore, for how long, and within what timeframe.
How does FLEXAMIT determine what you need?
FLEXAMIT does not only look at whether there is technically "a backup".
We consider:
- which Microsoft 365 data is business-critical;
- how long recovery points are needed;
- how quickly recovery must be possible;
- which built-in Microsoft 365 recovery options already exist;
- where additional backup is useful or necessary;
- which retention and GDPR requirements apply;
- how access to backups is secured;
- how restore procedures are monitored.
We combine Microsoft 365 knowledge, security, backup, retention, and recovery so that you do not only discover after an incident what is and is not recoverable.
Our cybersecurity expertise was recognised three years in a row by our Microsoft distributor with the Cybersecurity Partner of the Year award.
Would you like to know if your Microsoft 365 data is sufficiently protected and recoverable today?
Contact us at:
sales@flexamit.com
Data lost?
Have you accidentally deleted files, emails, or other Microsoft 365 data?
Recovery options may depend on retention periods and configuration.
If you are a FLEXAMIT customer, contact us as soon as possible via:
support@flexamit.com
Please specify as precisely as possible what disappeared, from where, and when you last saw it.
In summary
- Microsoft 365 has a very robust infrastructure and various built-in recovery options.
- That is not automatically the same as an independent full backup strategy.
- Recycle bins, versioning, and retention each have their own purpose and limitations.
- Microsoft now also offers Microsoft 365 Backup as a separate backup service.
- Your organisation must decide for itself which data it must be able to restore, for how long, and how quickly.
- Backup also protects against human errors, malicious deletion, and certain incidents.
- Backup data itself must be well secured.
- Backup retention must also fit within GDPR and the organisation's retention policy.
- A backup must not only exist but also be verifiably recoverable.
- "It's in the cloud" is not a full backup strategy.
Comments
0 comments
Please sign in to leave a comment.