We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Microsoft 365 Backup
Microsoft 365 Backup, UAE

The question is not whether you have a backup. It is how long a full restore takes when a thousand sites are encrypted.

Microsoft 365 Backup runs inside the service data boundary, which is why its restore speeds are measured in hours rather than weeks. Microsoft makes the argument itself: recovering large volumes from a remote air-gapped location can take weeks or months to get the business running again.

Book a Microsoft 365 backup reviewSee the restore point model
Microsoft 365 Backup for UAE organisations
  • 10 minutesStandard restore point interval
  • 1 yearRetention across all three workloads
  • Same or new URLRestore in place or beside the original
  • In the boundaryData never leaves the Microsoft 365 trust boundary
What it does

Seven things that decide whether this is the right backup for you.

Microsoft 365 Backup covers all or selected SharePoint sites, OneDrive accounts and Exchange mailboxes. Its design choice is speed of recovery over portability: backups are created within the protected services own data boundaries, which produces recovery times that off-tenant backup cannot match and a set of trade-offs you should understand before choosing it.

Ten minute restore points, and express points for speed

OneDrive and SharePoint carry ten minute standard restore points for the prior two weeks, roughly daily express restore points which may be weekly, and weekly points from two to fifty two weeks prior. Exchange Online carries ten minute restore points for the prior fifty two weeks. Retention is one year on all three, and express points are what deliver the fastest restores.

Restore speed is about site count, not data volume

Microsoft is explicit that restore is not dependent on the amount of data but on the number of sites and the type of restore point chosen. Published median expectations run from thirty minutes for a single OneDrive or SharePoint unit with an express restore point, to up to two hundred and fifty protection units per hour at a thousand units and above.

A full site restore is a rollback, and it overwrites

Microsoft states that a full site or OneDrive restore rolls back to the state at the prior point in time, overwriting all content and metadata created since. That is what you want after ransomware and precisely what you do not want when recovering one deleted folder. File version restore behaves differently, rolling the file forward while retaining prior versions.

Append-only rather than fully immutable, deliberately

Microsoft defines immutability as storage that cannot be altered, deleted or overwritten for a period, and states that Backup follows that definition except for disallowing deletion. Backups cannot be modified or overwritten, protecting against service or malware overwrites, but deletion remains possible so customers can offboard. Three defences approximate the rest.

Data residency is preserved, which matters in the UAE

Microsoft states that data never leaves the Microsoft 365 data trust boundary and honours the geographic locations of your current data residency, with only limited metadata such as tenant and site identifiers sent to Azure for billing. For organisations under UAE data residency expectations, that removes the argument that a backup copy has left the jurisdiction.

Exchange restores differ from the other two

Exchange restores mail, contacts, calendar and task items, at full mailbox or item level, restoring only modified or deleted items from the prior point in time, to the same or a new folder within the user mailbox. There is no express restore point concept for Exchange, and Microsoft states it does not need one.

Consumption billing rather than per-user licensing

Microsoft describes a pay-as-you-go offering charged on consumption, unlike traditional user-based licences, with restores free of charge. That is a different budgeting shape from every third-party backup product, and it means the cost follows how much data you protect rather than how many people you employ. We size it against your actual tenant.

The detail that changes your runbook

Rolling a site back overwrites everything created since that point in time.

This is documented behaviour and it is exactly right for the scenario the product was built for. It is exactly wrong for the scenario people usually reach for backup.

  • Quoted: a full site restore, and a OneDrive account restore, rolls back to the state of the site at the prior point in time, overwriting all content and metadata since that prior point in time.
  • After a ransomware event that encrypted a thousand sites, that is precisely what you want, and it is why the restore is fast. Everything since the event is worthless anyway.
  • When a user deleted one folder yesterday and the site has been in normal use since, a rollback would destroy a day of legitimate work across the whole site to recover one folder.
  • The runbook therefore needs two distinct procedures with two distinct approval levels, and the granular option, restoring a file to a prior version while retaining later versions, has to be the default that people reach for first.
Ask us to write your restore runbook
How we approach it

Four things that turn a protection policy into an actual recovery capability.

Turning Microsoft 365 Backup on is a short exercise. Being able to use it correctly under pressure, on the day it matters, requires work that almost nobody does in advance.

We write two runbooks, not one

A full site rollback overwrites everything created since the restore point, which is right after ransomware and catastrophic for a single deleted folder. Those are two different procedures with two different approval levels, and separating them in advance is what prevents a well-meaning restore destroying a day of work across a department.

We work out your actual recovery time before you need it

Restore speed follows the number of protection units and the restore point type, not the volume of data. Microsoft publishes median expectations by unit count, and express restore points are materially faster than standard ones. Translating that into a number of hours for your worst realistic scenario is what makes the recovery objective real rather than aspirational.

We set up the defences around the backup itself

Backups are append-only rather than fully immutable, because deletion has to remain possible for offboarding. The compensating controls are a fixed ninety day recovery grace period after offboarding, retention isolated from Purview policies, and multi-admin email notification when a potentially harmful action is taken on the Backup tool. All three get configured deliberately.

We test a restore before anyone calls it protected

Including the timings, because policy activation alone takes on average up to sixty minutes to process and another sixty to create restore points, and initial backups run at roughly fifteen minutes per thousand protection units. Knowing those numbers from your own tenant is worth considerably more than knowing them from documentation.

Where this fits

Six UAE situations where in-tenant backup is the right answer.

The strength is recovery speed at scale inside the Microsoft 365 boundary. Where that is what you need, nothing off-tenant competes. Where you need a copy outside the tenant, this is a complement rather than a replacement.

An organisation recovering from a large ransomware event

This is the scenario the product was designed around. Microsoft describes the difficulty of copying data at scale from a remote air-gapped location, which can take weeks or months. In-place rollback to an express restore point, across many sites at once, is measured in hours, and that difference is the whole argument.

A regulated firm under data residency expectations

Data never leaves the Microsoft 365 data trust boundary and honours your current data residency locations, with only limited metadata such as tenant and site identifiers going to Azure for billing. For UAE organisations that have had to justify where every copy of their data lives, that removes an argument rather than creating one.

A firm whose exposure is a departing employee, not malware

Deliberate deletion by someone with legitimate access is at least as common as ransomware and far less dramatic, so it is often noticed weeks later. Exchange ten minute restore points cover the prior fifty two weeks, and mail, contacts, calendar and task items can be restored to a new folder in the mailbox rather than overwriting current state.

A business with a single very large SharePoint estate

Because restore speed follows the number of sites rather than the volume of data, an estate with a few enormous sites behaves very differently from one with thousands of small ones. Modelling that against the published performance expectations is the difference between a recovery objective you can meet and one you have written down.

An organisation that has never tested a Microsoft 365 restore

Which is most of them. Retention policies and recycle bins are frequently believed to be backup, and they behave completely differently under a mass encryption event. A tested restore, with a measured duration from your own tenant, converts an assumption into a capability and usually adjusts somebody expectation in the process.

A multi-geo tenant across several countries

Microsoft states that Backup supports sites and user accounts from both the central and satellite locations. For UAE headquartered groups with entities in other regions, that avoids the split arrangement where the head office is protected by one product and the satellite locations are protected by nothing anybody can name.

Three positions

How UAE organisations protect Microsoft 365 data.

The right hand column is more common than anyone admits, and it usually rests on a belief that the recycle bin and retention policies constitute a backup. They do not, and they behave very differently under a ransomware event.
SharePoint, OneDrive and Exchange covered
Microsoft 365 BackupYes
Third-party off-tenant backupUsually more workloads
Recycle bin and retention onlyPartly
Recovery point interval
Microsoft 365 Backup10 minutes
Third-party off-tenant backupVaries, often daily
Recycle bin and retention onlyNot applicable
Mass restore speed
Microsoft 365 BackupHours
Third-party off-tenant backupDays to weeks
Recycle bin and retention onlyNot applicable
Data stays in the Microsoft 365 boundary
Microsoft 365 BackupYes
Third-party off-tenant backupNo
Recycle bin and retention onlyYes
Copy outside the tenant
Microsoft 365 BackupNo
Third-party off-tenant backupYes
Recycle bin and retention onlyNo
Protection against backup overwrite
Microsoft 365 BackupAppend-only
Third-party off-tenant backupVaries
Recycle bin and retention onlyNone
Retention isolated from Purview policies
Microsoft 365 BackupYes
Third-party off-tenant backupYes
Recycle bin and retention onlyNo
Restore charges
Microsoft 365 BackupFree
Third-party off-tenant backupVaries
Recycle bin and retention onlyNot applicable
Billing shape
Microsoft 365 BackupConsumption
Third-party off-tenant backupPer user or per workload
Recycle bin and retention onlyNone
Useful after a large ransomware event
Microsoft 365 BackupYes
Third-party off-tenant backupSlowly
Recycle bin and retention onlyNo
Feature
Microsoft 365 Backup
Third-party off-tenant backup
Recycle bin and retention only
SharePoint, OneDrive and Exchange covered
YesUsually more workloadsPartly
Recovery point interval
10 minutesVaries, often dailyNot applicable
Mass restore speed
HoursDays to weeksNot applicable
Data stays in the Microsoft 365 boundary
YesNoYes
Copy outside the tenant
NoYesNo
Protection against backup overwrite
Append-onlyVariesNone
Retention isolated from Purview policies
YesYesNo
Restore charges
FreeVariesNot applicable
Billing shape
ConsumptionPer user or per workloadNone
Useful after a large ransomware event
YesSlowlyNo
The three workloads

What is covered, and how each behaves differently.

Reproduced from the published feature summary. The differences between the columns are what most restore plans get wrong.
AspectOneDriveSharePointExchange Online
Retention period1 year1 year1 year
Standard restore points10 minute, for the prior two weeks10 minute, for the prior two weeks10 minute, for the prior 52 weeks
Longer term pointsRoughly daily express, weekly 2 to 52 weeks priorRoughly daily express, weekly snapshots 2 to 52 weeks priorNot applicable, 10 minute points run the full year
Backup granularityOneDrive accountSharePoint siteExchange user account
Restore granularityAccount, with file version restore coming soonSite, with file version restore coming soonMail, contacts, calendar and task items
Restore locationSame or new URLSame or new URLSame or new folder in the mailbox
Restore behaviourRollback overwrites content and metadata since that pointRollback overwrites content and metadata since that pointRestores only modified or deleted items from that point
Express restore pointsYes, and they are the fast pathYes, and they are the fast pathNot present and not required
AuditabilityActions fully auditableActions fully auditableActions fully auditable
Geographic residencyRedundant, replicated, honours tenant residencyRedundant, replicated, honours tenant residencyRedundant, replicated, honours tenant residency
How an engagement runs

Five steps, and the restore test is not optional.

Typically three to six weeks. Enabling protection is quick. Agreeing scope, measuring real recovery times and writing the runbooks is the work that makes it useful.
  1. 1

    Establish what needs protecting and what it will cost to run

    All sites and mailboxes, or a selected set. Because billing is consumption based rather than per user, the scope decision has a direct commercial consequence, and we size it against your actual data volumes rather than a headcount. Multi-geo tenants are included, since both central and satellite locations are supported.

  2. 2

    Agree the recovery objectives against published behaviour

    Ten minute standard restore points, one year retention, and restore speeds that follow unit count rather than data volume. We translate the published median expectations into hours for your worst realistic scenario, then confirm whether the business accepts that number or needs a different approach for part of the estate.

  3. 3

    Configure protection and the defences around it

    Protection policies activated, with the expectation set that activation takes up to sixty minutes to process and another sixty to create restore points, and initial backups run at roughly fifteen minutes per thousand protection units. Multi-admin notification recipients configured, and the ninety day offboarding grace period understood by whoever holds admin rights.

  4. 4

    Write two runbooks and rehearse both

    A mass rollback procedure for a destructive event, with the appropriate approval level given that it overwrites everything since the restore point, and a granular procedure for the everyday case. Both rehearsed against real restore points, with the actual elapsed times recorded from your own tenant.

  5. 5

    Decide whether you still need a copy outside the tenant

    This product keeps data inside the Microsoft 365 trust boundary, which is a strength for residency and a limitation for anyone whose policy requires an independent copy. That is a deliberate decision to make with a clear head rather than an assumption to discover during an incident, and for some organisations the answer is both.

Straight answers

What organisations ask about Microsoft 365 Backup.

All or selected SharePoint sites, OneDrive accounts and Exchange mailboxes. Those three workloads are what the published feature summary covers. If your requirement includes other Microsoft 365 data, that needs a separate answer rather than an assumption, and it is one of the first things we establish.

Ten minute standard restore points. For OneDrive and SharePoint those cover the prior two weeks, supplemented by roughly daily express restore points which may be weekly, and weekly points from two to fifty two weeks prior. For Exchange Online, ten minute restore points run for the prior fifty two weeks. Retention is one year across all three.

Faster than off-tenant backup, and the speed depends on the number of protection units rather than the volume of data. Published median expectations include thirty minutes for a single OneDrive or SharePoint unit using an express restore point, two hours for a single Exchange mailbox, and up to two hundred and fifty protection units per hour at a thousand units and above. In-place restores beat restores to a new URL.

A recommended restore point presented in the restore workflow that yields the quickest recovery, sometimes significantly faster than a standard one. Microsoft notes that high speed restores come from using express restore points, and that using a standard point for OneDrive and SharePoint may be significantly slower, especially for small-scale restores. Exchange Online has no express restore point concept and does not require one.

A full site or OneDrive account restore does, and Microsoft says so plainly: it rolls back to the state at the prior point in time, overwriting all content and metadata created since. File version restore behaves differently, rolling the file forward to the prior state while retaining prior versions. Exchange restores only modified or deleted items from that point. Knowing which you are running matters enormously.

Append-only rather than fully immutable, and Microsoft is precise about the distinction. Immutability means storage that cannot be altered, deleted or overwritten for a period. Backup meets that definition except for disallowing deletion, because customers need the ability to offboard. The backups cannot be modified or overwritten by the service or by malware, which is the protection that matters most.

Three published defences. A fixed ninety day recovery grace period after offboarding, working like a soft-delete recycle bin so backups can be recovered for ninety days. Retention and deletion policies, including those from Purview, do not affect the backup retention period, which stays fully isolated. And a multi-admin email notification feature that automatically notifies a preset group of admins if a potentially harmful action is taken on the Backup tool.

Inside the Microsoft 365 data trust boundary. Microsoft states that data never leaves it and that the geographic locations of your current data residency are honoured, with only limited metadata such as tenant and site identifiers sent to Azure for billing purposes. Backups are physically redundant and geographically replicated. For UAE data residency conversations, that is a materially simpler position than an off-tenant copy.

For recovery speed inside the tenant, it is difficult to beat. For an independent copy held outside the Microsoft 365 boundary, it does not attempt to compete, because keeping data inside the boundary is the design decision that makes it fast. Organisations whose policy requires an out-of-tenant copy should treat this as a complement. Many run both, for different reasons.

It is not licensed per user. Microsoft describes a pay-as-you-go offering that charges based on consumption, unlike traditional user-based licences, with restores free of charge. That means cost follows how much data you protect. We size it against your actual tenant and confirm current rates with you rather than publishing a figure that may have changed.

Microsoft states that once you submit a request to activate a valid protection policy, it takes on average up to sixty minutes to process and another sixty minutes to create restore points, with initial backups taking approximately fifteen minutes per thousand protection units added to a policy. Restore points are created in the service as soon as the policy is confirmed active, even if they take longer to become visible in the restore tool.

Yes. Microsoft states that Microsoft 365 Backup supports the backup of sites and user accounts from both the central and satellite locations. For UAE headquartered groups with entities elsewhere, that avoids the common arrangement where the head office is protected and the satellite locations quietly are not.

Yes, the published feature summary states that actions are fully auditable across all three workloads. That matters more than it sounds, because a restore is a high-impact administrative action, particularly the rollback variety that overwrites current content. Reviewing restore actions belongs in the same rhythm as reviewing any other privileged operation.

Yes. Microsoft partners with independent software publishers to provide versions of their applications integrated with the Microsoft 365 Backup Storage platform, delivering the same underlying performance. For a partner application, operation of the tool is managed and paid for entirely through that partner application, which can give a single view across data estates beyond Microsoft 365.

We scope per organisation, driven by the volume of data in scope, whether you want the runbooks written and rehearsed with you, and whether an out-of-tenant copy is also required. The product itself bills on consumption rather than per user, so the sizing conversation comes from your actual tenant data rather than from a headcount estimate.
Before you turn it on

Fifteen questions that make the difference between backup and recovery.

The first group is scope, the second is the recovery objective the business actually has, and the third is the operational reality that only matters on the worst day.

Scope

  • All sites and mailboxes, or selected?
    Both are supported, and it drives consumption.
  • Is your tenant multi-geo?
    Central and satellite locations are both supported.
  • What is not covered by this product?
    The published scope is three workloads.
  • Do you also need a copy outside the tenant?
    A separate decision, not a substitute.
  • How much data are you protecting?
    Consumption billing follows volume.

Recovery objectives

  • What recovery point does the business need?
    Ten minutes is the standard interval.
  • How many sites in a worst case?
    Restore speed follows unit count.
  • Is one year of retention enough?
    That is the published period.
  • In place or to a new URL?
    In place is faster.
  • Who approves a full rollback?
    It overwrites everything since that point.

Operations

  • Have you tested a restore?
    An untested backup is an assumption.
  • Who is on the multi-admin notification list?
    It flags harmful actions on the tool.
  • Do you know the 90 day offboarding grace period?
    It is your last line if backups are deleted.
  • Are restore actions audited and reviewed?
    They are auditable by default.
  • Is the runbook written before the incident?
    Nobody writes a good one during.
Related reading

The pages around this one.

Backup as a service

The vendor-neutral view, including out-of-tenant copies and non-Microsoft workloads.

Learn more

Backup audit

Establishing whether what you have would actually restore, before you need it to.

Learn more

Ransomware protection

The controls that stop the event this product exists to recover from.

Learn more
Next step

Ask how many hours a full restore of your SharePoint estate would take.

It is a specific number, it follows from your site count and restore point type, and almost nobody knows theirs. Working it out takes an afternoon and it usually changes the conversation about what protection you need.

Book a Microsoft 365 backup reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Backup as a Service

M365, endpoint, server backup, immutable

Learn more

Backup and Restore Audit

We test whether your backups actually restore

Learn more

Ransomware Protection

Defender XDR and Sentinel-driven ransomware defense

Learn more

DRaaS

Tested disaster recovery on Azure

Learn more

Data Backup

Automated backup and data protection

Learn more

Microsoft 365

Complete Microsoft 365 setup, migration & support

Learn more

Business Continuity Planning

BCP, RPO/RTO design, and DR runbook authoring

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy