How to Evaluate a Microsoft 365 Backup Solution: What Actually Matters
Introduction
Selecting a Microsoft 365 backup solution requires a transition from understanding the necessity of backup to evaluating technical execution. While the distinction between native retention and third-party backup has been established in previous analysis regarding Cloud Backup vs Microsoft 365 Retention, the focus must now shift to the specific parameters that define an enterprise-grade recovery framework. An effective evaluation identifies whether a solution provides operational continuity or merely satisfies a compliance checkbox.
This document provides a structured framework for assessing backup providers based on workload coverage, storage architecture, recovery mechanics, and resilience against modern threats.
What Workloads Are Actually Covered?
A comprehensive backup strategy must account for the entire Microsoft 365 ecosystem. Partial coverage creates data silos and recovery gaps that can disrupt business operations.
Exchange Online
Evaluation must confirm the backup of all mailbox types. This includes primary user mailboxes, shared mailboxes, resource mailboxes (rooms and equipment), and archive mailboxes. Assessment should verify that calendar entries, contacts, and tasks are captured alongside email data.
SharePoint Online and OneDrive for Business
Coverage must extend beyond document libraries. Evaluation should confirm the capture of site collections, sub-sites, lists, and individual file versions. For OneDrive, the solution must handle the full folder structure and permissions associated with each user’s personal storage.
Microsoft Teams and Microsoft 365 Groups
Teams architecture is complex, with data distributed across Exchange, SharePoint, and Azure. An evaluation must verify the backup of:
- Channel conversations (Public and Private).
- Files shared within channels and 1:1 chats.
- Wiki tabs and OneNote notebooks.
- Team membership and settings.
Configuration Metadata
Data alone is insufficient for rapid recovery. A professional solution must capture configuration metadata. This includes folder structures, sharing permissions (internal and external), and site settings. Without metadata backup, a restoration may result in “flat” data that requires significant manual effort to re-secure and re-organize.
Where Is the Backup Stored?
The physical and logical location of backup data determines its resilience against tenant-level compromise.
Same Tenant vs. Independent Environment
Storing backups within the same Microsoft 365 tenant or the same Azure AD (Entra ID) environment creates a single point of failure. If the primary tenant is compromised via administrative credential theft, the “backups” may be equally vulnerable to deletion.
Off-Platform Storage
A valid evaluation criterion is the use of off-platform storage. The backup data should reside in a separate, independent cloud environment (e.g., a proprietary backup cloud or a different public cloud provider) with its own authentication stack. This ensures that a total outage or compromise of Microsoft 365 does not impact the availability of the backup data.
Immutability Controls
Immutability ensures that once data is written to the backup storage, it cannot be altered or deleted for a specified duration, even by an administrator with high-level privileges. This is a critical defense against insider threats and ransomware. Evaluation should confirm if the solution supports Write Once, Read Many (WORM) storage.

Figure 1: Backup architecture comparison: integrated (same-tenant) vs independent off-platform storage.
Recovery Granularity and Scope
The utility of a backup solution is measured by its restoration capabilities. Evaluation must focus on the “Restore” side of the interface.
- Individual Item Restore: The ability to recover a single email, a specific file version, or a single calendar appointment without affecting the rest of the dataset.
- Folder and Site Restore: The capability to roll back an entire folder or SharePoint site to a specific point in time.
- Full Mailbox or Site Restore: Necessary for employee offboarding or total data loss scenarios.
- Cross-User Restore: The ability to restore data from one user’s backup into another user’s account, which is essential for legal discovery or staff turnover.
- Tenant-Level Restoration: In extreme scenarios, the solution should provide a pathway to restore the core structure of the tenant’s data.
Defining Recovery Objectives (RTO/RPO)
A structured evaluation must align technical performance with business requirements through two primary metrics: Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
Recovery Time Objective (RTO)
RTO defines the maximum acceptable duration for a restore operation. Evaluation should assess the solution’s throughput and the complexity of the recovery interface. A solution that takes 48 hours to restore a 50GB mailbox may fail to meet the RTO of a critical business unit.
Recovery Point Objective (RPO)
RPO defines the maximum acceptable amount of data loss, measured in time. If a backup runs once every 24 hours, the RPO is 24 hours. For high-velocity environments, evaluation should prioritize solutions offering multiple backup snapshots per day (e.g., 4 to 6 snapshots) to minimize data gaps.
Testing and Verification
The presence of a “Success” log in a backup dashboard does not guarantee a successful restore. Evaluation should include the solution’s ability to perform automated recovery testing. Regular verification ensures that the data is not only backed up but is also readable and restorable.

Figure 2: RTO / RPO framework: snapshot frequency (RPO) vs restoration speed (RTO).
Compliance and Auditability
Data protection is often driven by regulatory requirements. The evaluation must confirm that the solution supports long-term data governance.
- Custom Retention Periods: Organizations may require 7 years of data retention for financial records or indefinite retention for legal purposes. The solution must allow for granular retention policies that exceed Microsoft’s default settings.
- Legal Hold: The ability to preserve specific data indefinitely, regardless of the general retention policy, for ongoing litigation or investigations.
- Audit Logging: A professional solution must maintain detailed logs of who accessed the backup, what was restored, and when. This is essential for maintaining a chain of custody and fulfilling compliance audits.
Ransomware Resilience
Modern ransomware specifically targets backup repositories to prevent recovery without payment.
Role Separation and Access Control
Evaluation should check for Multi-Factor Authentication (MFA) enforcement on the backup portal. Furthermore, the solution should ideally support “Four-Eyes” authentication, where critical actions (like deleting a backup set) require approval from two separate administrators.
Isolated Backup Access
The credentials used to manage Microsoft 365 should never be the same credentials used to manage the backup environment. True resilience is achieved when the backup system operates on a separate identity provider, ensuring that a compromised Global Admin account in Microsoft 365 cannot access the backup storage.
Common Red Flags
During the evaluation process, certain phrases and configurations should be identified as indicators of insufficient protection:
- “We rely on Microsoft retention policies.”
Retention is a versioning tool, not a backup. It lacks the air-gapped isolation required for disaster recovery. - “We export PST files periodically.”
Manual exports are inconsistent, lack central management, are prone to corruption, and do not cover Teams or SharePoint data. - “Microsoft handles that automatically.”
The Microsoft Shared Responsibility Model explicitly states that data protection and backup are the responsibility of the customer. - “Backups are stored in our Azure Blob storage (same tenant).”
This creates a logical dependency. If the tenant is locked or compromised, the backups are inaccessible.

Figure 3: Recovery granularity spectrum: individual item restore through to tenant-level restoration.
Conclusion
Evaluating a Microsoft 365 backup solution requires a shift from passive trust to active verification. The primary objective is to ensure that data remains available, immutable, and restorable regardless of the failure state of the primary Microsoft 365 environment. Strategic assessment should focus on workload depth, storage independence, and the precision of recovery tools.
If organizations are unsure how their current Microsoft 365 environment is protected, a structured review can identify potential gaps in coverage or recovery capability. For more information on securing organizational data, visit the Moreton Bay I.T. Microsoft 365 services page.
