
"It's in the cloud, Microsoft backs it up." Every IT lead has heard this, and it is half true. Microsoft is responsible for the availability of Microsoft 365 as a service. Recovering your data after your own users, your own administrators or an attacker with your credentials have deleted or encrypted it is your responsibility.
What the platform protects against
Datacentre failure, hardware loss, service outages. Microsoft replicates data across facilities and offers uptime commitments. Native retention and recycle-bin features give you a window to undo mistakes.
What it does not protect against
- Deletion past the retention window. Once the recycle-bin and retention periods lapse, the data is gone.
- Ransomware that reaches the tenant. An attacker with a user's or an admin's credentials can encrypt, delete or exfiltrate through the same interfaces the user has.
- Malicious or careless administrators. The same rights that let an admin fix things let them destroy things.
- Legal, regulatory and residency requirements. Native features are not designed to prove an immutable history or to keep copies inside a specific country.
What a backup layer has to add
An independent copy, on independent infrastructure, with its own identity plane. Specifically:
- Coverage across the tenant: Exchange mailboxes, OneDrive, SharePoint and Teams, not just mail.
- Frequent recovery points: minutes, not a nightly snapshot, so a bad afternoon does not cost a whole day.
- Immutability: a write-once copy that cannot be altered before its retention expires, even by someone holding stolen credentials.
- An air gap: a tier that production cannot reach except during controlled transfer windows.
- Geo-bounded storage: copies that stay in the country or region your regulator expects.
- Anomaly detection: watching the backup streams for the deletion spikes and encryption patterns that mark an attack, so you find out early rather than at restore time.
How OctoVault approaches it
OctoVault is Third Octopus's backup and data-protection platform for Microsoft 365 and enterprise infrastructure. It journals Exchange mail in real time, backs up OneDrive and SharePoint, keeps an immutable compliance ledger and admin access audit logs, and holds an isolated write-once copy on an air-gapped tier with recovery points under 15 minutes. Storage is geo-bounded, which is what India's DPDP Act and the UAE's data protection rules tend to require.
The question to ask your team is not "do we have a backup?" but "which copy survives if our global admin account is compromised tonight?"
There is a free Microsoft 365 backup assessment at octovault.thirdoctopus.com that shows what is and is not protected in your tenant today.


