Skip to content

A direct IT practice — Canadian professional firms

White Glove Request an introduction
Menu

Backup & recovery

Know exactly what is backed up—and that it actually restores.

Security essentials mentions, in passing, that backups are checked for whether they would actually restore. This is that promise made concrete: what is backed up, how often a restore is actually tested, and how far back you can recover—stated as specific facts, not a reassuring generality.

What is actually backed up

A useful backup starts with a specific, written answer to what is backed up, where it goes, and how often—not an assumption.

Microsoft 365 mailboxes and files

Exchange Online mailboxes, OneDrive, and SharePoint document libraries are backed up independently of Microsoft’s own short-term retention, since native retention is not the same thing as a restorable backup.

Servers and endpoint data

Any remaining on-premises server, plus business-critical folders on desktops and laptops, are included in the backup scope by explicit agreement, not assumed to be covered just because a device is centrally managed.

What is excluded, named plainly

Personal files, non-business accounts, and anything outside the agreed scope are stated up front, so a gap is a known boundary, not a surprise during a real recovery.

Proving the restore, and knowing the limits

A backup job reporting success proves it ran. It does not prove the data comes back usable, or say how far back you can reach.

Scheduled restore tests, documented

A sample restore is performed and verified on a recurring schedule; anything that does not come back cleanly is investigated, and the result is recorded rather than quietly rerun until it passes.

Retention windows stated plainly

How many days back you can recover a file, an email, or a deleted mailbox item is a specific, documented number, not an assumption based on whatever Microsoft happens to keep by default.

Isolated from the event it protects against

Backup copies are kept isolated from a ransomware or mass-deletion event on live data, and version history in OneDrive or SharePoint is treated as a convenience for accidental edits, not a substitute for that isolated copy.

What this is—and what a full DR plan requires

Being specific about backup scope does not turn this into a certified disaster-recovery engagement, and it should not be sold as one.

Backup and restore, not certified BCDR

This keeps Microsoft 365 and device data recoverable on a known schedule; it is not a certified disaster-recovery or business-continuity engagement with contractual recovery-time guarantees.

The delivery side of continuity readiness

Continuity planning names decision owners and workarounds for an interruption; this is the mechanism that makes a stated recovery point something you can actually reach.

Formal DR design stays separate

Multi-site failover, formal recovery-time and recovery-point contracts, and a certified business-continuity program are specialist engagements, scoped and priced as their own project.

Prepare this

A useful conversation starts with simple facts.

  • Which Microsoft 365 services and devices are backed up today
  • Last time a restore was actually tested, and what happened
  • Current retention window for deleted items and file versions
  • Whether backup copies are isolated from a ransomware scenario
  • Any prior data-loss incident and how it was resolved

Bring the context; keep credentials out of the message.

Request an introduction

Prepare a useful introduction

Describe the interruption, the change ahead, and how your team prefers to be kept informed. A short note is enough to begin a service-fit conversation.

Required fields are marked with an asterisk (*).

Never include passwords, keys, recovery codes, or account-access details.

Read the privacy policy to understand how this request will be handled.