Microsoft 365 gives Australian organisations incredible resilience, but it doesn’t replace backup. Boards, auditors and the OAIC want evidence that your business can actually restore data when it matters. This guide explains exactly what to back up across Exchange Online, SharePoint, OneDrive and Teams; how to test restores in a way that stands up to scrutiny; and how to report compliance with confidence. You’ll also find an RPO/RTO worksheet and a monthly verification routine you can adopt today.
Microsoft operates on a shared responsibility model. In Microsoft 365, Microsoft ensures the platform is available and resilient; you’re responsible for your data, identity and governance.
What Microsoft covers
– Service uptime and infrastructure availability
– Physical security and hyper-scale redundancy across data centres
– Native features like recycle bins, versioning and basic retention windows
What you still own
– Protection from accidental deletion, admin error, malicious insiders and ransomware
– Long-term, point-in-time restores beyond native retention windows
– Compliance-grade immutability, audit trails and reporting
– Alignment with OAIC expectations and board risk appetite
Why this matters by workload
– Exchange Online: Deleted Items and Recoverable Items help in short windows, but aren’t a long-term or immutable backup. Shared mailboxes and group mailboxes need coverage too.
– SharePoint Online and OneDrive: Recycle bins and versioning are useful, but can be bypassed or emptied. Metadata and permissions also need to be restorable.
– Microsoft Teams: Teams data lives across services (chat in Exchange, files in SharePoint/OneDrive, wikis/notebooks in OneNote). Comprehensive backup must capture those dependencies and support granular restore (messages, channels, tabs) as well as full-workspace rollback.
Bottom line: native features are not a substitute for tested, immutable backups with business-defined RPO/RTO.
A complete backup strategy covers data, structure and security context, not just files and emails.
Exchange Online
– User mailboxes, archives, shared mailboxes and resource mailboxes
– Calendars, contacts and tasks
– Microsoft 365 Group mailboxes and public folders where used
– Granular and full-mailbox restore options with point-in-time recovery
SharePoint Online
– Site collections, subsites, lists and libraries
– File versions, metadata, permissions and site settings
– Hub/site structure and navigation
– Granular (single file/list item) and full-site restore capability
OneDrive for Business
– Files, folders, versions and sharing permissions
– Deleted user OneDrive content with retention aligned to HR offboarding
– Granular and entire-OneDrive recovery
Microsoft Teams
– Standard, private and shared channels (messages, posts and channel structure)
– Files stored in SharePoint/OneDrive
– Tabs, apps and wiki/OneNote content
– Team settings and membership to reconstitute workspaces
– Ability to restore at the message/channel/team level or full tenant scope
Don’t forget supporting context
– Microsoft 365 Groups that underpin Teams and SharePoint access
– Optional: exportable configurations (e.g., key policies) to speed recovery of the collaboration fabric after a major incident
Immutability is the difference between “we have backups” and “we can prove backups survived the attack.”
– Write-once, read-many (WORM) storage: Use immutable policies that prevent deletion or modification for a defined retention period.
– Off-platform copies: Keep a logically separate backup copy outside the primary tenant to break ransomware blast radius.
– 3-2-1-1-0 approach: 3 copies, 2 media types, 1 offsite, 1 immutable, 0 restore errors in testing.
– Australian data residency: Store backups in Australian regions to support APP 8 (cross‑border data flows) and your contractual obligations.
– Key management: Use strong access controls and, where available, customer-managed keys with strict separation of duties.
Tip: Azure Blob immutable policies or S3‑compatible object lock are common options. If you need a managed approach, AZ Cloud Solutions can configure immutable, AU‑resident backup storage as part of our Backup & continuity service: https://azcloudsolutions.com.au/
Microsoft Purview retention policies and Litigation/Legal Hold are critical for eDiscovery and regulatory requirements, but they are not backups.
Use them for
– Preserving content for legal matters or industry retention rules
– Governing how long content is kept or deleted, centrally and consistently
– Searching and exporting content for compliance purposes
Do not rely on them for
– Fast rollback to a clean point in time after ransomware
– Restoring entire mailboxes, sites or Teams with structure and permissions intact
– Protecting against administrative mistakes (e.g., a hold removed by error)
Best practice
– Run retention/holds and backups together. Document how they complement each other in your Information Governance plan.
– Avoid over-retention that bloats storage and risk. Right-size retention in both backup and Purview policies to your legal and business requirements.
Use this worksheet with business owners. Keep it simple and consistent.
Step 1: Identify your key processes
– Examples: Client onboarding, payroll, project delivery, clinical bookings, claims processing.
Step 2: Map each process to Microsoft 365 workloads
– Email/calendar (Exchange), files (SharePoint/OneDrive), collaboration (Teams).
Step 3: Set target RPO (how much data you can afford to lose) and RTO (how fast you must be back)
– Tier 1: Mission critical (e.g., finance close, patient bookings)
– Tier 2: Important (e.g., team collaboration spaces)
– Tier 3: Nice-to-have
Copy/paste template
– Process name:
– Owner:
– Workloads used: Exchange / SharePoint / OneDrive / Teams
– RPO target: [e.g., 15 minutes, 1 hour, end of day]
– RTO target: [e.g., 2 hours, 4 hours, next business day]
– Minimum restore scope to meet RTO: [single item / mailbox / site / team / tenant subset]
– Evidence during testing: [restore time, validation steps, user sign-off]
Example targets to sanity-check
– Exchange Online (Tier 1 mailboxes): RPO 15–60 minutes, RTO 2–4 hours
– SharePoint critical sites: RPO 1–4 hours, RTO same business day
– OneDrive general users: RPO 4–24 hours, RTO next business day
– Teams critical channels: RPO 1–4 hours, RTO same business day
These are starting points; confirm with owners and the board.
Run restore tests that mirror real incidents, collect evidence and track success over time.
1) Define scope and cadence
– Monthly: Spot tests of single-item restores in each workload
– Quarterly: Point-in-time mailbox/site/team restores
– Annually: Scenario-based test (e.g., ransomware in a project site; executive mailbox compromise)
2) Prepare a safe test environment
– Use non-production mailboxes/sites/teams or create temporary “Restore Validation” targets
– Restrict test data to non-sensitive content unless approved by your Privacy Officer
– Pre-authorise downtime windows and communications
3) Execute scenario-based tests
– Single email/file/message restore:
– Find a specific deleted email/file/message and restore to original location
– Validate permissions and metadata are intact
– Point-in-time restore:
– Restore a mailbox or site to a specific timestamp before a simulated incident
– Validate folder structure, versions and sharing links
– Full workspace reconstitution (Teams):
– Restore a team with channels, tabs and files
– Validate membership and app tabs
– Ransomware simulation:
– Introduce a controlled “encrypted” file set to a test site
– Restore to a clean point; confirm all infected files replaced and no persistence
4) Validate and sign off
– Technical validation: Compare item counts, versions, metadata and permissions
– Business validation: Owner confirms the restored content is fit for purpose
– Performance validation: Record actual RTO vs target; note bottlenecks
5) Capture immutable evidence
– Backup job IDs and timestamps
– Screenshots/exports of successful restores
– Audit logs showing who performed the action and where data was restored
– Sign-off from the process owner and IT approver
Adopt a repeatable routine your board and auditors will recognise.
Weekly
– Review backup job status and address failures within 24 hours
– Spot-restore one item from each workload and record the outcome
Monthly
– Rotate through business units to restore:
– One mailbox to a point in time
– One SharePoint site library to a point in time
– One Teams channel’s messages and files
– Verify immutability status on your backup repository and note expiry dates
– Reconcile licence/seat coverage to ensure all users and new Teams/sites are protected
– Update the RPO/RTO log with actuals; raise variances as risks
Quarterly
– Tabletop incident exercise (e.g., ransomware or insider deletion)
– Test an end-to-end restore including user acceptance
– Review retention and Legal Hold configurations with Legal/Privacy
Annually
– Full audit of backup scope, storage location (AU residency), encryption, keys and access controls
– Restore a representative sample of “leaver” data to validate HR offboarding coverage
What auditors and the OAIC expect
– Reasonable steps to protect personal information (APP 11), which includes the ability to recover quickly from incidents
– Evidence of governance: documented policies, defined roles, and tested controls
– Traceability: audit logs and chain-of-custody during restores
– Cross-border data handling (APP 8): where backups are stored and who can access them
What your board wants to see on one page
– Coverage: what workloads and how many users/sites/teams are under backup
– Health: last 30 days of backup success/failure, with any remediations
– Assurance: last test date, what was restored, RPO/RTO achieved vs target
– Risk/exceptions: gaps, variances, upcoming changes
– Compliance: AU data residency status, immutability status, retention alignment
Copy/paste board report template
– Executive summary:
– No. of protected users/sites/teams:
– Success rate last 30 days:
– Issues resolved:
– Assurance highlights (this month):
– Tests performed:
– RPO/RTO achieved:
– Variances and actions:
– Compliance posture:
– Backup storage region(s):
– Immutability window:
– Retention vs policy mapping:
– Access review (who can restore/back up):
– Risks and recommendations:
– Open gaps:
– Planned improvements and timelines:
– Sign-offs:
– IT owner:
– Business owner(s):
– Privacy/Legal (if applicable):
Retain these reports and supporting evidence for at least 12 months so you can demonstrate a sustained control, not a one-off effort.
– Relying solely on recycle bins/versioning: These can be purged, bypassed or expire before you notice a problem.
– Gaps in coverage: New users, Teams and SharePoint sites not auto‑protected.
– No immutability: “Backups” that ransomware can encrypt or delete are not backups.
– Unverified restores: Untested backups create a false sense of security and board exposure.
– Retention sprawl: Overlapping retention policies and holds that inflate storage and complicate eDiscovery.
If you’d rather not reinvent the wheel, AZ Cloud Solutions can implement and run the whole program under a predictable monthly fee.
– Backup & continuity: Immutable backups for Microsoft 365, tested restores, and a documented plan for when something goes wrong. Learn more at https://azcloudsolutions.com.au/
– Managed Microsoft 365: Mailboxes, Teams and SharePoint administered, optimised and supported so your people can focus on work. https://azcloudsolutions.com.au/
– Cybersecurity & Defender: Essential Eight–aligned hardening with Microsoft Defender and Sentinel monitoring to reduce the chance of an incident in the first place. https://azcloudsolutions.com.au/
– Reporting you can read: Plain-English monthly reports on uptime, tickets and security posture, including backup verification.
– Local AU support, 7 days: A Microsoft-certified team that lives in Microsoft 365 every day, on your time zone, with AU data residency as standard.
Book a free, no‑obligation assessment of your Microsoft 365 environment and we’ll show you where your backup posture stands today — and what we’d do first to improve it: https://azcloudsolutions.com.au/
For Australian SMBs, “we think backups are running” isn’t enough. You need immutable backups across Exchange Online, SharePoint, OneDrive and Teams; retention and Legal Hold that complement, not replace, backup; regular restore testing; and clear reporting that satisfies the OAIC and your board. With a simple RPO/RTO worksheet, a monthly verification routine and the right partner, you can prove your backups work — not just that they exist — and get back to running your business with confidence.
#Microsoft365 #Backup #BusinessContinuity #Compliance #OAIC #Ransomware #Australia #AZCloudSolutions