# How Should Microsoft 365, Email and SaaS Data Be Backed Up?

**URL:** https://securesys.com.tr/en/learning/backup-and-business-continuity/backing-up-microsoft-365-and-saas-data

![How Should Microsoft 365, Email and SaaS Data Be Backed Up?](/images/bilgi-merkezi/covers/cover-backup-10.webp)

Many organizations, after moving to Microsoft 365, Google Workspace and similar SaaS platforms, believe their critical data is automatically and fully protected.

E-mail is no longer on the Exchange server inside the company.

The files are on OneDrive or SharePoint.

Team work is carried out over Teams.

User accounts are managed through Entra ID.

For this reason a certain idea forms in some organizations:

**“Microsoft already backs the data up. We do not need to take a separate backup.”**

This approach can be risky.

The cloud provider can offer strong mechanisms around infrastructure availability, hardware durability and service continuity.

However, this does not mean the organization can return to whatever point it wishes in every data loss scenario.

For example;

a user can delete thousands of e-mails by mistake,

an administrator can remove a critical SharePoint site,

ransomware can encrypt files synchronized with OneDrive,

a compromised account can delete data,

a retention policy can be configured wrongly,

a former employee's data can be lost while their account is being removed.

**For this reason a separate backup and recovery strategy is necessary in SaaS environments too.**

### What Is Microsoft 365 Backup?

Microsoft 365 Backup is the protection of critical data inside Microsoft 365 with an independent or additional backup layer.

Among this data;

Exchange Online e-mail,

OneDrive files,

SharePoint sites,

Teams data

may be found.

The purpose is not merely to store the data.

The purpose is:

**to be able to return to the desired point in time in a trusted and controlled way.**

### Where Is Microsoft 365 Data Located?

Microsoft 365 is not a single application.

It consists of more than one service.

For example:

**Exchange Online → e-mail, calendar, mailbox data**

**OneDrive → user files**

**SharePoint Online → corporate documents and site content**

**Microsoft Teams → messages, team structures, files and collaboration data**

For this reason the backup plan must assess each service's data structure separately.

### Why Is Exchange Online Backup Necessary?

E-mail is one of the critical data sources for corporate businesses.

E-mails;

customer communication,

contract processes,

quotations,

accounting records,

project decisions

can contain these.

A mailbox deleted by mistake or maliciously can cause serious business loss.

For this reason the recovery strategy for Exchange Online data must be clearly defined.

### Can Deleted E-mail Be Recovered in Microsoft 365?

Certain retention and recovery mechanisms may exist.

However, unlimited-period recovery is not possible in every scenario.

For this reason the organization must answer this question:

**“Can we definitely recover an e-mail deleted six months ago?”**

If the answer is not clear, the need for long-term backup must be assessed.

### Are Retention and Backup the Same Thing?

No.

This is one of the most important distinctions in the SaaS world.

A Retention Policy:

determines how long the data will be kept.

Backup:

creates independent restore points of the data.

Retention is a data management policy.

Backup, meanwhile, is a recovery mechanism.

### What Is Legal Hold?

Legal Hold is a preservation mechanism used to prevent certain data from being deleted for legal or investigative purposes.

For example, the e-mails of a user involved in litigation can be preserved even if they are deleted.

However, Legal Hold does not replace a general backup.

Because its purpose is:

**data preservation, not operational recovery.**

### Does a Microsoft 365 Retention Policy Replace Backup?

In the full sense, no.

A Retention Policy can ensure the data is kept.

However, backup systems;

bulk restore,

point-in-time recovery,

cross-user restore,

separate storage,

independent management

can offer additional capabilities such as these.

For this reason the two approaches can be used together.

### Why Is OneDrive Backup Necessary?

In many organizations OneDrive is used to synchronize users' desktop and document folders.

This provides great convenience.

However, that same synchronization mechanism can create risk in a ransomware attack.

### How Can Ransomware Affect OneDrive Files?

Let us imagine ransomware running on a user's computer.

The files are encrypted.

The OneDrive sync client detects these files as changes.

The encrypted files can be synchronized to the cloud environment.

For this reason using cloud storage does not entirely eliminate ransomware risk.

### Is Versioning Enough Against Ransomware?

Versioning is an important protection mechanism.

It can provide the ability to return to earlier versions of a file.

However, in very large attacks;

restoring thousands of files,

the version history being limited,

account compromise

problems such as these can emerge.

An independent backup can make bulk recovery processes easier.

### Why Is SharePoint Backup Important?

SharePoint is not merely a file storage area.

It can contain corporate;

intranet,

document libraries,

project sites,

workflows,

permission structures

as its content.

A site collection deleted by mistake or a wide-ranging permission change can create a serious operational problem.

### Is SharePoint Restore Only File Restore?

No.

Real recovery;

site,

library,

folder,

file,

permission,

metadata

can be done at these levels.

For this reason the backup solution must understand the SharePoint structure.

### Why Is Teams Backup Complex?

Microsoft Teams is in fact a combination of many Microsoft 365 services.

For example, files inside Teams most often reside on SharePoint or OneDrive.

Messages can be stored in different services.

For this reason “Teams backup” does not mean backing up a single data source.

### What Should Teams Backup Cover?

According to need;

Teams structures,

channels,

messages,

files,

team memberships

can be assessed.

Which Teams components the backup product in use actually protects must be checked.

### What Is SaaS Backup?

SaaS Backup is copying data in cloud-based applications to an independent backup platform.

For example;

Microsoft 365,

Google Workspace,

Salesforce,

CRM systems,

cloud-based ERP applications

can be brought into backup scope.

### What Is Cloud-to-Cloud Backup?

Cloud-to-Cloud Backup is copying data in a SaaS or cloud service to another cloud storage or backup environment.

For example:

Microsoft 365

↓

Independent backup cloud

This way a recovery area separate from the production SaaS environment is created.

### Why Is Cloud-to-Cloud Backup Important?

If the production account is entirely compromised, the independent backup environment can be used.

For this reason using;

a separate identity,

a separate tenant,

a separate cloud account

can increase security.

### What Is the Shared Responsibility Model?

One of the fundamental concepts in cloud and SaaS security is the:

#### Shared Responsibility Model

that is:

**the model of shared responsibility.**

The cloud provider is responsible for certain layers of the platform.

The organization, meanwhile;

user accounts,

access privileges,

data management,

retention,

the backup strategy,

endpoint security

can be responsible for subjects such as these.

### Is the SaaS Provider Obliged to Recover Every Piece of Data?

Not in every case.

The retention and restore limits the provider offers depend on the contract and the service features.

For this reason, rather than relying on the provider's features, the organization must determine its own recovery requirements.

### How Is RPO Determined in Microsoft 365 Backup?

The RPO is determined according to the acceptable data loss period.

For example, for a critical mailbox:

RPO = 1 hour

can be set.

In that case the backup platform may need to provide roughly hourly data protection.

### How Is RTO Determined in Microsoft 365 Backup?

RTO is not only about the existence of the backup.

It also;

restore speed,

API limits,

data volume,

network,

user count

depends on factors such as these.

For example, a single e-mail can be restored within a few minutes.

But an entire 5 TB SharePoint environment can take far longer.

### What Is API Throttling?

SaaS platforms can limit API usage.

This is called:

#### API Throttling

in cloud terminology.

If a backup or restore operation makes too many API calls, the service can temporarily apply rate limiting.

This can affect the RTO particularly in large restore operations.

### Why Must a Large Restore Be Tested in SaaS Backup?

A single-file restore test may succeed.

But in a real disaster;

500 users,

thousands of mailboxes,

terabytes of files

may need to be restored.

For this reason small restore tests alone may not show the real capacity.

### What Is Microsoft 365 Tenant Compromise?

Tenant Compromise is the attacker obtaining high privileges in the Microsoft 365 environment.

For example, a Global Administrator account can be compromised.

In that case the attacker;

can change users,

can affect MFA policies,

can reach mailboxes,

can delete SharePoint data.

For this reason keeping backup accounts inside the same trust boundary is risky.

### Should the Global Administrator Be the Backup Admin?

Where possible, separation of duties must be applied.

One account holding unlimited privileges over both the Microsoft 365 tenant and the backup system increases the blast radius.

For this reason:

the Microsoft 365 admin

and

the backup admin

accounts can be separated.

### Is MFA Mandatory for SaaS Backup?

In a critical backup environment it must be applied strongly.

Especially;

the backup portal,

restore operations,

administrator login

must be protected with MFA.

### Can Conditional Access Be Used?

Yes.

Backup administrator access;

a specific device,

a specific country,

a specific IP,

a compliant device

can be restricted with conditions such as these.

This is useful particularly on cloud backup management consoles.

### Should the SaaS Backup Admin Account Be a Daily User Account?

No.

An account used for daily e-mail and web browsing carries high risk.

It can be compromised through phishing.

The backup admin account must be separate and protected with tighter security policies.

### Can a Privileged Access Workstation Be Used?

In critical organizations, yes.

The backup administrator can perform management only from a hardened PAW.

This method reduces phishing and endpoint malware risk.

### Should SaaS Backup Data Be Encrypted?

Yes.

Backup data must be encrypted both:

#### In Transit

and:

#### At Rest

in both states.

This is critical particularly in e-mail and document backups.

### Who Should Hold the Encryption Key?

This can vary according to the backup solution in use.

The organization;

a provider-managed key

or

a customer-managed key

can use either.

What matters is that the key management responsibility is clear.

### Can SaaS Backup Be Immutable?

Yes.

The backup platform can support immutable storage or Object Lock.

This is important particularly against administrator compromise and ransomware risk.

### Can Microsoft 365 Backup Be Air-Gapped?

In the physical sense it can be difficult.

However, a logical air gap can be created.

For example;

a separate backup tenant/account,

a different identity,

immutable storage,

restricted API access

can be used.

### Is Backup Inside the Same Tenant Risky?

It is not entirely wrong.

However, in a tenant-wide administrator compromise scenario, the risk of the backup environment being affected too must be assessed.

In critical institutions, creating a separate security boundary can be stronger.

### Why Is Backup Important After E-mail Account Compromise?

When the attacker reaches a mailbox they can not only read mail but delete mail or create rules.

For example:

a forward rule,

an inbox rule,

mail deletion

can be applied.

Backup ensures past e-mail records are preserved.

### The Relationship Between Business Email Compromise and Backup

In Business Email Compromise – BEC attacks the attacker can reach the e-mail account.

In some cases they delete mail to hide their traces.

Backup can help bring back old e-mails during post-incident forensic examination.

### Can Backup Be Used for Forensic Purposes?

Yes.

Past mailbox data can be valuable for incident investigation.

For example, the attacker's first phishing e-mail may have been deleted.

It can be brought back from the backup.

However, in forensic processes, data integrity and chain of custody requirements must be assessed separately.

### How Long Should Mailbox Backups Be Kept?

There is no single correct period.

Retention;

business need,

legal requirements,

regulation,

storage cost

must be determined taking these into account.

For example, some data can be kept for a few years.

However, unnecessarily long retention can also increase data risk.

### What Happens to a User's Data When They Leave?

This is one of the most critical subjects in offboarding processes.

When the user's account is deleted;

the mailbox,

OneDrive,

Teams data

can be affected.

For this reason data ownership and the retention process must be planned before the employee leaves.

### What Is Leaver Backup?

Keeping the mailbox and OneDrive data in backup for a defined period once an employee leaves the organization can be thought of as the:

#### Leaver Backup

approach.

This way access to the old data can be possible even after the license is removed.

### What Happens If the Microsoft 365 License Is Removed?

Data retention behaviour can vary according to the service used and the retention configuration.

For this reason the organization must test and document its offboarding procedure.

Backup can provide additional security in this process.

### Can OneDrive Be Restored from One User to Another?

A good backup system:

User A's file

to user B

or to an alternative location can restore it.

This is useful particularly when an employee leaves.

### How Is a SharePoint Site Restore Performed?

According to the recovery need;

full site,

library,

folder,

file

a restore can be done at these levels.

Granular restore capability reduces the operational time.

### What Is Granular Restore?

Granular Restore is bringing back only the required object rather than the whole backup.

For example:

a single mail,

a single file,

a single folder,

a single user

can be restored.

This is very important particularly for SaaS backup.

### Is a Full Tenant Restore Possible?

It depends on the backup product.

However, in the real world, restoring an entire Microsoft 365 tenant all at once can be quite complex.

For this reason the recovery priority must be determined in advance.

### How Is SaaS Recovery Priority Determined?

For example:

Priority 1 → management and critical operations mailboxes

Priority 2 → finance and sales

Priority 3 → general users

an ordering along these lines can be made.

The same approach can be applied to SharePoint sites as well.

### How Should an Exchange Online Restore Test Be Performed?

A sample test:

- A test e-mail is created.
- A backup is taken.
- The e-mail is deleted.
- The restore operation is performed.
- The content and attachment are checked.
- The restore time is measured.

### OneDrive Restore Test

During the test;

file deletion,

ransomware-like file modification,

folder restore,

alternate location restore

scenarios can be applied.

### SharePoint Restore Test

Not only files but also;

metadata,

permissions,

versions

this information must be verified as well.

### Teams Restore Test

Which Teams data the solution in use protects must be tested.

For example;

channel,

file,

team structure,

message

restore capabilities can be examined separately.

### SaaS Backup Monitoring

The backup system must be monitored on a daily basis.

For example;

a failed job,

an authentication failure,

an API error,

a license issue,

storage full,

a backup delay

must generate an alarm.

### How Critical Is a Backup Job Failure?

If there are 500 users in the Microsoft 365 environment, a few days of backup failure can create a serious data gap.

For this reason a backup failure must not be merely an informational message.

If it is not resolved within the defined period, escalation must be applied.

### Can SaaS Backup Be Integrated with SIEM?

Yes.

These events in particular can be sent to SIEM:

administrator login,

a restore operation,

backup deletion,

a retention change,

an MFA change,

API access failure.

These events are valuable from a security monitoring perspective.

### Should Restore Operations Be Logged?

Absolutely.

An administrator restoring or exporting thousands of mailbox e-mails may not be normal behaviour.

For this reason restore operations must be audited.

### Backup Export Risk

Backup solutions sometimes offer a data export feature.

For example, a mailbox can be downloaded as a PST.

If this feature is used without authorization it creates a data exfiltration risk.

For this reason export privileges must be restricted.

### Does DLP Protect Backup Data?

DLP mostly monitors production data movements.

Because backup storage is a separate area, it may not fall directly under the same control.

For this reason access to the backup repository must be protected separately.

### Is Backup Data Sensitive Data?

Yes.

A backup generally contains a full copy of the data on the production system.

For this reason it can in some cases be even more valuable than production.

Because inside a single backup file;

thousands of mailboxes,

customer data,

employee data,

documents

may be found.

### Microsoft 365 Backup from a KVKK Perspective

If there is personal data inside the backup, that data must be protected from a KVKK perspective as well.

Among the subjects to watch;

access control,

retention,

encryption,

destruction,

transfer of data abroad

may be found.

### If SaaS Backup Data Is Kept Abroad

The backup provider's data centre location matters.

Keeping backups containing personal data abroad can require a legal assessment in terms of data transfer.

For this reason the data location must be learned before the contract.

### Backup Retention and Data Minimization

Keeping a backup for an unlimited period is not always safer.

Unnecessary data;

legal,

privacy,

cyber security

can increase risk in these areas.

For this reason retention must be determined according to business and regulatory need.

### SaaS Backup and ISO 27001

From an ISO/IEC 27001 perspective, data in cloud and SaaS systems must have its;

confidentiality,

integrity,

availability

requirements protected on a risk basis.

Backup is, in this scope, one of the important controls supporting data availability and recovery capability.

### ISO 22301 and SaaS Recovery

If critical business processes depend on Microsoft 365 or another SaaS platform, the loss of those services must be assessed in the business continuity plan as well.

For example, if Microsoft 365 is unreachable:

How will communication be provided?

How will files be reached?

Is there an alternative communication system?

These subjects cannot be solved with backup alone.

### The SaaS Provider Outage Scenario

Large platforms such as Microsoft 365 have high availability.

However, no system is one hundred percent uninterrupted.

In a provider outage, having the backup data can be useful.

However, working directly from the backup without access to the production SaaS service is not always possible.

For this reason a BCP must be planned separately.

### Alternative Business Continuity for E-mail

In critical organizations, during a major SaaS outage;

an alternative domain,

an emergency mailbox system,

telephone or messaging

methods such as these can be evaluated.

Backup provides only the past data.

### The Difference Between SaaS Backup and High Availability

The SaaS provider's high availability:

keeps the service running.

Backup, meanwhile:

provides the ability to go back in the event of data loss.

These two concepts are not alternatives to each other.

### The Difference Between SaaS Backup and Archive

An archive is used more for long-term retention and search.

Backup, meanwhile, is designed for fast or reliable recovery.

For example, an e-mail archive system can be used for compliance.

But a separate backup may be needed for mailbox disaster recovery.

### The Difference Between SaaS Backup and eDiscovery

eDiscovery;

legal search,

investigation,

data examination

is used for these purposes.

Backup, meanwhile, carries a restore purpose.

They can support each other but they are not the same.

### What Should Be Looked at When Choosing a SaaS Backup Vendor?

When choosing a solution these questions can be asked:

Which Microsoft 365 services does it support?

Is there granular restore?

Is there immutable backup?

In which country is the data kept?

Is there encryption?

Does it support MFA?

How long is the retention?

How is API throttling managed?

Is tenant-to-tenant restore possible?

What is the bulk restore performance like?

Is there an audit log?

### How Should a SaaS Backup SLA Be Assessed?

The backup platform's uptime alone must not be looked at.

In addition;

backup success rate,

restore time,

support response,

data durability

must be assessed.

### Why Is an Exit Plan Important for SaaS Backup?

When the backup provider is changed, how the old data will be obtained must be known.

For example:

Is bulk export possible?

In which format?

Within what time?

Is there an additional charge?

These questions reduce vendor lock-in risk.

### A Sample Architecture for Microsoft 365 Backup

An enterprise structure may look like this:

#### Microsoft 365 Tenant

↓

#### Backup API / SaaS Connector

↓

#### Independent Backup Platform

↓

#### Separate Backup Account

↓

#### Encrypted & Immutable Storage

↓

#### Long-Term Retention

In this architecture the security boundary of the backup is separated from the production SaaS environment.

### Should There Be a Different Backup Policy for Critical Users?

There can be.

For example;

senior management,

finance,

legal,

R&D

users can carry a higher criticality level.

For these, longer retention or more frequent backups can be applied.

### Why Must VIP Mailboxes Be Specially Protected?

VIP mailboxes carry high value for attackers.

In the CEO's or CFO's mailbox;

financial information,

strategic plans,

customer correspondence

may be found.

For this reason the recovery and audit policies can be stricter.

### Should Shared Mailboxes Be Brought into Backup Scope?

Yes.

Shared mailboxes sometimes carry critical business processes.

For example:

sales@

finance@

support@

accounts such as these must be included in the backup scope.

### Public Folders Must Not Be Forgotten

If the organization still uses Public Folders, this data must be brought into the backup scope as well.

### The Most Common Mistakes in Microsoft 365 Backup

The mistakes frequently seen in organizations are as follows:

- the assumption “Microsoft already backs it up”,
- mistaking retention for backup,
- backing up only e-mail and forgetting SharePoint and OneDrive,
- leaving Teams data outside the scope,
- using the backup admin account as the Global Admin,
- not using MFA,
- not performing restore tests,
- not accounting for API throttling,
- not knowing the backup data location,
- not planning the backup policy for when an employee leaves,
- not testing bulk restore performance.

### Microsoft 365 Backup Checklist

The organization must be able to answer these questions clearly:

Is there Exchange Online backup?

Is there OneDrive backup?

Is there SharePoint backup?

What is the Teams backup scope?

How long is the retention period?

Is immutable backup in use?

Is the backup independent of the production tenant?

Is MFA in use?

In which country is the backup data?

Is encryption active?

Has the restore been tested?

Has the bulk restore time been measured?

These questions are a strong starting point for understanding SaaS backup maturity.

### Conclusion: Using SaaS Does Not Remove the Backup Responsibility

Microsoft 365 and other SaaS platforms offer the advantage of high availability and strong infrastructure.

However, using these services does not eliminate data loss risks such as:

wrong deletion,

account compromise,

ransomware,

a retention error,

an administrator error,

an offboarding problem

as the list shows.

For this reason, in modern SaaS security, backup must be treated as a separate security layer.

In a strong SaaS backup architecture;

**Cloud-to-Cloud Backup,**

**Immutable Storage,**

**Encryption,**

**MFA,**

**a separate backup admin,**

**Long-Term Retention,**

#### Granular Restore

and **Restore Testing**

must be used together.

The most critical principle is this:

**The SaaS provider keeping the service running and the organization being able to return its own data to any point in time are not the same thing.**

For this reason a Microsoft 365 backup strategy must be designed not only with the question:

“Is the data in the cloud?”

but with the question:

**“If this data is deleted by mistake, encrypted, or the administrator account is compromised, how do we come back independently?”**

with this question in mind.

Real SaaS resilience begins at this point.
