Backing up Microsoft 365, properly
Mail, contacts, calendars, tasks, OneDrive and SharePoint backed up outside the tenant, on your server — and restored down to the individual message.
The misunderstanding that costs dearly
"Our data is in the cloud, it is backed up."
It is the sentence every service provider has already heard at a client's. Microsoft guarantees the availability of its service and the redundancy of its infrastructure. What happens for the content is down to the client: a folder deleted and purged, a mailbox closed after someone leaves, a SharePoint library overwritten during a migration, ransomware that encrypts a workstation and propagates the encrypted files to OneDrive.
The Microsoft recycle bin and retention cover some of these cases, over a limited window, and provided nobody has changed them. An independent backup, outside the tenant, on storage you control, covers the rest.
What is backed up
| Item | Detail |
|---|---|
| Mailboxes | Mail and the complete folder tree |
| Contacts | Users' address books |
| Calendriers | Events, split into yearly windows to keep recurrences under control |
| To-Do tasks | Lists and tasks attached to the accounts |
| OneDrive | Files and folders in personal spaces |
| SharePoint | Sites, document libraries and lists |
One Office 365 licence covers the mailbox, OneDrive and SharePoint of the same user.
Agentless, through the Graph API
The backup is performed by the BeBackup server, which queries Microsoft Graph. Nothing is installed on the workstations, nothing is deployed in the tenant beyond the application registration. The Azure application is provisioned from the BeBackup interface, with OAuth2 authentication.
Subsequent backups are incremental, using Graph delta tokens: only the items added or changed since the last pass are retrieved. Calendars are split into yearly windows, which keeps a recurring series from inflating the processed volume indefinitely.
The content lands in an ordinary BeBackup medium. That matters to an operator: the 365 data inherits exactly the same treatment as everything else — versions, deduplication, AES-256 encryption, integrity checking by hashes, tiered retention, off-site replication.
Finding an item, not restoring a tenant
The whole restore is driven from the browser, with no third-party tool.
- Browsing the mailbox folder tree
- Preview of messages and their attachments
- Full-text search in message bodies
- Search across contacts, events and tasks
- Browsing OneDrive items
- Restore to the original mailbox
- Restore to another mailbox
- Restore to a SharePoint library
- Permissions checked before writing
- Files exported without restoring into the tenant
It is the difference between "we have a backup" and "I will have that email back to you in two minutes".
Frequently asked questions
Does Microsoft not already back up my 365 data?
Microsoft guarantees the availability of the service and the replication of its infrastructure. Responsibility for the content — an item deleted, a folder overwritten, a mailbox emptied after someone leaves, ransomware encryption synchronised to OneDrive — stays with the client. That is what the shared responsibility model describes.
Does an agent have to be installed on the workstations?
No. The Microsoft 365 backup is performed by the BeBackup server itself, through the Microsoft Graph API. No software is deployed on the workstations or in the tenant.
How is the Azure application registered?
The Azure application is provisioned from the BeBackup interface, with OAuth2 authentication. There is no manifest to edit by hand and no secret to copy across.
Where is the backed-up data stored?
In an ordinary BeBackup medium, on the server you have chosen: the same versions, the same deduplication, the same encryption and the same integrity checking as the rest of your backups. They therefore leave the Microsoft infrastructure.
Can it be restored to a mailbox other than the original?
Yes. The restore can target the original mailbox, another mailbox, or a SharePoint library, with permissions checked beforehand. Files can also be exported without being restored into the tenant.
How are the rate limits imposed by Microsoft handled?
Download concurrency can be set medium by medium, which allows the load to be matched to the throttling Microsoft applies to the tenant concerned.
Offer 365 backup to your clients
A thirty-minute demonstration is enough to see the Azure provisioning, a backup and a granular restore from end to end.
The other pages in this section Features
- What's new in v7 Microsoft 365, BeBackup Drive, agents for macOS, Linux, Synology, Android and iPhone…
- You are here Microsoft 365
- System and virtualisation SmartImage, disk image, VSS for SQL Server and Hyper-V, VMware VMs backed up agentlessly with…
- Restore and recovery A file, a folder, a partition, a whole disk, a physical machine to an ESXi VM, booting under…
- For service providers Multi-client console, white label, per-technician rights, quotas and a real-time dashboard…
- Security and encryption AES-256 encryption on the workstation, key held by the client, TLS 1.3, two-factor…
Contact the BeBackup team
Would you like to know more about our BeBackup backup solution?