A Microsoft 365 backup review should start with a straightforward question: if a member of staff deletes a critical Teams file, mailbox folder or SharePoint library today, how quickly could you restore it with confidence? For many organisations, the answer is less certain than expected. Microsoft 365 is a highly resilient cloud platform, but platform resilience is not the same as having a recoverable copy of your business data.
That distinction matters when email, documents, conversations and operational records are spread across Exchange Online, OneDrive, SharePoint and Teams. A sensible backup arrangement protects productivity when mistakes happen, supports a measured response to cyber incidents and reduces the disruption caused by staff changes, retention gaps or failed migrations.
What Microsoft 365 protects – and what it does not
Microsoft provides the infrastructure behind Microsoft 365. Its service is designed for availability, with multiple safeguards against major platform failures. For most organisations, that means the service itself is dependable.
However, Microsoft 365 operates on a shared responsibility model. Microsoft protects the service; your organisation remains responsible for the data created, stored and managed within it. That includes deciding who can delete information, how long data should be retained and whether a separate copy is needed for recovery.
Native features such as version history, recycle bins, retention policies and litigation holds are valuable. They should be configured properly, particularly where regulatory or safeguarding requirements apply. But they are not automatically a complete backup strategy. Retention preserves information according to a policy. Backup is intended to create an independent copy that can be found and restored when the original is missing, damaged or inaccessible.
The difference becomes clear in real situations. A recycle bin has a limited retention period. A retention policy may preserve a record but make a fast, user-friendly restore difficult. A synchronised OneDrive deletion can affect files across devices. If a compromised account has enough permissions, an attacker may also attempt to remove or encrypt data held in the live environment.
Microsoft 365 backup review: the questions that matter
A useful review is not a box-ticking exercise or a search for the longest feature list. It should establish which information matters most to your operation, how long you can work without it and what a successful recovery looks like.
Begin with scope. Many businesses assume that backing up Exchange Online means Microsoft 365 is covered. It does not. Email may be protected while SharePoint sites, OneDrive folders, Teams channels and the files associated with them are not. Teams is especially easy to underestimate because its content is distributed between Teams, SharePoint, Exchange and OneDrive.
Then consider recovery. Can an administrator restore a single email, file or folder without bringing back unwanted changes? Can they recover an entire user account after an accidental deletion? Can a SharePoint site be restored to an earlier point in time? These are practical questions that determine whether backup helps staff resume work or simply creates another technical problem to manage.
Finally, examine ownership. A backup service is only useful if named people know how to access it, permissions are protected and restores are tested. If an outsourced IT provider manages the system, responsibility for authorising, performing and validating a restore should be clear in the support agreement.
The risks are usually ordinary, not dramatic
Ransomware rightly receives attention, but it is not the only reason to maintain Microsoft 365 backups. Day-to-day events are more common and can be just as damaging when they involve a finance mailbox, a project site or sensitive pupil, customer or employee information.
The main scenarios to assess are accidental deletion, incorrect permissions changes, malicious activity, a departing employee removing files, synchronisation errors and mistakes during migration or restructuring. In manufacturing, the missing material might be a quality document or production instruction. In a school or academy trust, it may be a safeguarding-related record or teaching resource. In a growing business, it is often the shared folders that hold years of commercial knowledge.
A backup does not remove the need for identity protection, multi-factor authentication, staff awareness training or careful permissions management. It gives the organisation a recovery route when those controls do not prevent an incident completely.
What to look for in a backup service
The right service depends on your data volumes, risk profile and internal capability, but several requirements should be non-negotiable. The service should cover the Microsoft 365 workloads you rely on, retain data for a period that matches your needs and allow granular restores as well as larger recoveries.
Security deserves close attention. Backup administration should use separate, tightly controlled accounts with multi-factor authentication. Ask whether backup copies are encrypted in transit and at rest, how access is logged and whether deletion protection or immutable storage options are available. A backup platform that can be easily altered by a compromised administrator account offers less protection than it appears to.
Data location and contractual clarity also matter for UK organisations. Understand where backup data is stored, which suppliers are involved and how the arrangement supports your UK GDPR obligations. UK-based storage may be preferred by some organisations, but it is not a substitute for appropriate security, access controls and a documented data-processing position.
Do not overlook usability. During an incident, a complex recovery process costs time and creates uncertainty. The best solution is not necessarily the one with the most advanced console. It is the one your authorised team or technology partner can use quickly and safely, with a clear record of what was restored.
Set recovery targets before choosing retention
Retention periods are often chosen by habit. A business selects one year, three years or seven years because it sounds sensible, without linking the decision to actual operational and legal needs. A better approach is to define two targets.
Recovery point objective, or RPO, is the maximum amount of data loss you can accept. If backups run once a day, changes made after the last backup may be unavailable. Recovery time objective, or RTO, is how quickly you need the data restored. A critical mailbox required for customer service may need attention within hours, while a historic archive may tolerate a longer timeframe.
These targets should vary by workload where necessary. Daily backups may be appropriate for most files, while a busy SharePoint site supporting a live project could justify more frequent protection. Longer retention may be appropriate for records with contractual, financial or safeguarding implications. The key is to make a conscious choice rather than assume all data carries the same value.
Testing turns backup into resilience
A successful backup job is not proof of a successful recovery. Reports can confirm that data was copied, but only a restore test confirms that the required item can be located, recovered and opened in the right place.
Plan periodic tests that reflect realistic situations. Restore a deleted email into a test mailbox, recover an older version of a document and validate the process for a former employee’s OneDrive. Record the time taken, any permissions issues and who approved the activity. This gives senior leaders evidence that the arrangement works and gives IT teams a process they can follow under pressure.
For organisations with limited internal IT capacity, this is an area where a managed service can add real value. CETSAT typically approaches backup as part of a wider resilience plan, aligning Microsoft 365 protection with identity security, monitoring, disaster recovery procedures and day-to-day support.
Avoid treating backup as a standalone purchase
A backup platform cannot compensate for uncontrolled access or poorly organised data. If every user has broad permissions to sensitive SharePoint folders, a restore may recover deleted files but not prevent the same exposure recurring. Likewise, unmanaged leavers’ accounts and unclear ownership of Teams sites make both governance and recovery harder.
Use the review to improve the wider environment. Confirm that multi-factor authentication is enforced, privileged accounts are limited, inactive users are handled properly and key SharePoint sites have accountable owners. Check whether staff understand where official documents should be stored, rather than relying on personal OneDrive folders or email attachments.
This joined-up approach is usually more cost-effective than adding security tools one at a time. It also makes incident response calmer: people know what information is protected, who has authority to act and how normal work will be restored.
A backup service earns its place when it makes a difficult day shorter. Define the data that keeps your organisation moving, test the recovery route before it is needed and review the arrangement whenever Microsoft 365 use, staff structure or risk changes.

