Managed cyber security

Microsoft 365 Backup

Independent backup for Exchange, OneDrive, SharePoint and Teams.

What is Microsoft 365 Backup?

Microsoft 365 includes resilient infrastructure, retention options and service availability features, but these do not replace an independently managed backup designed for granular and tested recovery. 39Security protects Exchange Online, OneDrive, SharePoint and Teams data, monitors backup success and helps the business restore individual items or wider data sets when required.

Who is this service for?

Established small businesses using Microsoft 365 that rely on email, Teams, SharePoint or OneDrive for daily operations, especially where customer contracts, cyber insurance or internal governance require a clearly owned recovery process.

What problem does it solve?

Accidental deletion, malicious deletion, compromised administrator accounts, retention misconfiguration and ransomware can all create recovery gaps. Native recycle bins and retention can be valuable, but they may not provide the independent copy, long retention, simple search or documented restore testing a business expects after a serious incident.

What is included?

  • Discovery of Microsoft 365 tenants, users and priority data
  • Independent automated backup for Exchange, OneDrive, SharePoint and supported Teams data
  • Backup-job monitoring and exception investigation
  • Granular mailbox, file, folder and site recovery
  • Retention policy agreed around operational and contractual needs
  • Scheduled restore testing and recovery evidence
  • Monthly coverage and exception reporting

What is not included?

  • Unsupported third-party applications outside Microsoft 365
  • Unlimited forensic investigation after a major compromise
  • Data already deleted before the service starts
  • Legal discovery or compliance advice unless separately scoped

How implementation works

We confirm the tenant, licences, privileged accounts, retention objectives and recovery priorities. The backup platform is authorised using least-privilege access, initial protection is monitored through completion, and sample restores are performed. We then agree who may request a restore, how identity is verified and how urgent or large-scale recovery is escalated.

Supported platforms and products

Microsoft 365 Exchange Online, OneDrive for Business, SharePoint Online and supported Teams workloads. Coverage varies by Microsoft workload and backup platform, so the final scope and known limitations are documented before activation.

How quickly are alerts investigated?

Backup failures and material coverage gaps are reviewed on business days, with urgent exceptions escalated when they threaten agreed recovery objectives. A suspected compromise is handled through the incident-response route rather than treated as an ordinary backup ticket.

Who responds?

The named 39Security service team investigates failed jobs, validates platform health, coordinates with Microsoft or the backup vendor where required and performs authorised restores. Client contacts retain ownership of business approval, data sensitivity and communications to affected users.

What evidence and reporting will you receive?

Customers receive coverage information, exception records, restore-test results and a record of material recovery activity. These reports can support insurance renewals, customer questionnaires and continuity reviews, but they do not by themselves prove compliance with a particular standard.

Cyber Essentials, insurance and Microsoft 365

Independent backup supports resilience and recovery expectations commonly considered during Cyber Essentials planning, cyber-insurance reviews and Microsoft 365 governance. Cyber Essentials does not certify a backup product, and exact insurance requirements must be confirmed with the insurer.

What does it cost?

Pricing is normally per protected Microsoft 365 user, with a one-off setup charge. The live service page shows the current rate excluding VAT. Large SharePoint estates, unusual retention or high-volume recovery requirements may need a tailored quotation.

How is the service governed?

Before activation, the proposal should identify the covered users, devices, locations and platforms, together with the service window, escalation contacts and change responsibilities. During operation, material exceptions are recorded rather than hidden, and recommendations are separated into urgent actions, planned improvements and optional projects. This gives managers a practical view of risk, cost and ownership.

Service reviews should test whether coverage still matches the business. New starters, leavers, acquisitions, cloud applications, office moves and supplier changes can all create gaps. 39Security therefore treats onboarding, reporting and periodic review as part of the control, not as administration around the edge of the product.

What should good delivery look like?

A buyer should be able to identify what is protected, who is watching it, what happens when something goes wrong and which evidence will be available afterwards. The provider should explain limitations honestly, avoid vague promises and document any dependency on Microsoft licensing, internet connectivity, third-party suppliers or customer action. Clear boundaries make response faster and reduce disputes during an incident.

Questions to ask before selecting a provider

  • Which systems, users and locations are included in the quoted scope?
  • Who reviews alerts, during which hours, and what happens when the named contact is unavailable?
  • What evidence will we receive for clients, insurers, auditors or board reporting?
  • Which actions are included in the monthly fee and which require separate project approval?
  • How are service quality, response times, exclusions and exit arrangements documented?

Frequently asked questions

Does Microsoft 365 include backup?

Microsoft provides resilient services, recycle bins and retention capabilities, but these do not automatically provide an independently managed backup with separate administration, long-term retention and tested granular recovery. A dedicated backup service gives the business another recovery path when deletion, compromise or configuration errors affect the live tenant.

Can you restore one email or file?

Yes, where the item is inside the protected retention period. Granular recovery can normally restore an individual email, mailbox folder, OneDrive file, SharePoint item or supported Teams content without restoring the whole tenant.

How often are restores tested?

Restore testing is agreed during onboarding and repeated on a scheduled basis. The aim is to prove that protected data can be located and recovered, not merely that a dashboard shows successful backup jobs.

Does backup stop ransomware?

Backup does not stop an attack. It reduces the operational impact by providing a separate recovery source. Prevention, identity protection, EDR, email security and incident response are still required.