A common assumption at law firms using Microsoft 365 is that Microsoft backs everything up. It is an understandable belief, and it is partly true: Microsoft operates resilient infrastructure and protects against failures of its own platform. What most firms do not realize is that the shared responsibility model puts the protection of the firm's own data, including accidental deletion, malicious deletion, ransomware and account compromise, largely on the customer.
This post explains the gap and what to do about it.
Availability is not the same as backup
Microsoft's commitments focus on keeping the service running. They are not the same as promising that you can recover any file or mailbox to any point in time after you or an attacker removes it. Review Microsoft's current service agreement and documentation, which can change, rather than relying on assumptions.
How data is actually lost in Microsoft 365
- Accidental deletion. A user empties a folder or deletes a SharePoint library.
- Malicious insiders. A departing employee deletes files on the way out.
- Compromised accounts. An attacker with a stolen login deletes or encrypts mail and files, or sets rules that quietly erase messages.
- Ransomware sync. Encrypted files in OneDrive can sync to the cloud and overwrite good copies.
- Misconfigured retention. A policy that purges data earlier than expected, or an administrator error.
- License changes. When a user's license is removed, their data may be deleted after a grace period.
- Third-party integration errors. A faulty app that modifies or removes content.
What native features give you
Microsoft 365 includes recycle bins, version history and retention policies. These are helpful, with limits.
- Recycle bins hold deleted items for a limited period, after which they are permanently removed.
- Version history can help roll back a file, but versions can be lost or overwritten, and large-scale recovery is cumbersome.
- Retention and legal hold features are designed for compliance and preservation, not as a point-in-time recovery system.
- Administrators can change these settings, and so can an attacker who gains administrator access.
Some licenses include more advanced capabilities, such as ransomware recovery options for OneDrive. Check what your plan includes and test it.
What a separate backup adds
A third-party backup service takes independent copies of mailboxes, calendars, OneDrive, SharePoint and sometimes Teams data, and stores them outside your tenant.
- Independence: if the tenant is compromised, the backup is not.
- Point-in-time recovery: restore a mailbox or library to the state it was in last Tuesday.
- Longer retention under rules you control.
- Granular restores: recover a single email, folder or document.
- Protection from administrator mistakes and, with the right settings, from malicious deletion.
Questions to ask when choosing a backup service
- Which services are covered: Exchange mail, OneDrive, SharePoint, Teams, calendars, contacts?
- How often does it back up, and how long is data kept?
- Where is backup data stored, and is it encrypted?
- Is it immutable, so even our administrators cannot delete it?
- Are backup administrator credentials separate and protected by MFA?
- How quickly can we restore a whole mailbox, and a large SharePoint site?
- What are the contract terms for confidentiality and data return, given client data obligations under Model Rule 5.3 and related guidance?
- Can it support legal holds and e-discovery exports?
Law firm specifics
- Matter workspaces in SharePoint or Teams may have unique permission structures. Confirm they restore with permissions intact.
- Shared mailboxes for intake or billing should be included.
- Departed user data needs a retention plan that matches your records policy.
- Client outside counsel guidelines may ask about backup and recovery. A documented separate backup answers such questions well.
Test the restore
Pick a sample mailbox and a SharePoint folder each quarter. Restore them to an alternate location and confirm completeness, formatting and permissions. Record the time it took and the person who did it.
Do not forget the people
Teach users to contact IT immediately after accidental deletions, since recovery is easier in the first days. Tell staff that mailbox deletion is not a place to hide embarrassing messages; discoverability and retention rules apply.
Fit it into the 3-2-1 approach
Your live tenant is one copy. A separate backup is a second. Ideally one copy is immutable or offline, covering the "one offsite" principle.
How Counsel Cyber can help
Counsel Cyber deploys and monitors independent Microsoft 365 backup for law firms and tests restores on a regular schedule. If you would like us to check what your tenant retains today, we are glad to review it.