The question is not whether you have a backup. It is how long a full restore takes when a thousand sites are encrypted.
Microsoft 365 Backup runs inside the service data boundary, which is why its restore speeds are measured in hours rather than weeks. Microsoft makes the argument itself: recovering large volumes from a remote air-gapped location can take weeks or months to get the business running again.

- 10 minutesStandard restore point interval
- 1 yearRetention across all three workloads
- Same or new URLRestore in place or beside the original
- In the boundaryData never leaves the Microsoft 365 trust boundary
Seven things that decide whether this is the right backup for you.
Ten minute restore points, and express points for speed
OneDrive and SharePoint carry ten minute standard restore points for the prior two weeks, roughly daily express restore points which may be weekly, and weekly points from two to fifty two weeks prior. Exchange Online carries ten minute restore points for the prior fifty two weeks. Retention is one year on all three, and express points are what deliver the fastest restores.
Restore speed is about site count, not data volume
Microsoft is explicit that restore is not dependent on the amount of data but on the number of sites and the type of restore point chosen. Published median expectations run from thirty minutes for a single OneDrive or SharePoint unit with an express restore point, to up to two hundred and fifty protection units per hour at a thousand units and above.
A full site restore is a rollback, and it overwrites
Microsoft states that a full site or OneDrive restore rolls back to the state at the prior point in time, overwriting all content and metadata created since. That is what you want after ransomware and precisely what you do not want when recovering one deleted folder. File version restore behaves differently, rolling the file forward while retaining prior versions.
Append-only rather than fully immutable, deliberately
Microsoft defines immutability as storage that cannot be altered, deleted or overwritten for a period, and states that Backup follows that definition except for disallowing deletion. Backups cannot be modified or overwritten, protecting against service or malware overwrites, but deletion remains possible so customers can offboard. Three defences approximate the rest.
Data residency is preserved, which matters in the UAE
Microsoft states that data never leaves the Microsoft 365 data trust boundary and honours the geographic locations of your current data residency, with only limited metadata such as tenant and site identifiers sent to Azure for billing. For organisations under UAE data residency expectations, that removes the argument that a backup copy has left the jurisdiction.
Exchange restores differ from the other two
Exchange restores mail, contacts, calendar and task items, at full mailbox or item level, restoring only modified or deleted items from the prior point in time, to the same or a new folder within the user mailbox. There is no express restore point concept for Exchange, and Microsoft states it does not need one.
Consumption billing rather than per-user licensing
Microsoft describes a pay-as-you-go offering charged on consumption, unlike traditional user-based licences, with restores free of charge. That is a different budgeting shape from every third-party backup product, and it means the cost follows how much data you protect rather than how many people you employ. We size it against your actual tenant.
Rolling a site back overwrites everything created since that point in time.
This is documented behaviour and it is exactly right for the scenario the product was built for. It is exactly wrong for the scenario people usually reach for backup.
- Quoted: a full site restore, and a OneDrive account restore, rolls back to the state of the site at the prior point in time, overwriting all content and metadata since that prior point in time.
- After a ransomware event that encrypted a thousand sites, that is precisely what you want, and it is why the restore is fast. Everything since the event is worthless anyway.
- When a user deleted one folder yesterday and the site has been in normal use since, a rollback would destroy a day of legitimate work across the whole site to recover one folder.
- The runbook therefore needs two distinct procedures with two distinct approval levels, and the granular option, restoring a file to a prior version while retaining later versions, has to be the default that people reach for first.
Four things that turn a protection policy into an actual recovery capability.
We write two runbooks, not one
A full site rollback overwrites everything created since the restore point, which is right after ransomware and catastrophic for a single deleted folder. Those are two different procedures with two different approval levels, and separating them in advance is what prevents a well-meaning restore destroying a day of work across a department.
We work out your actual recovery time before you need it
Restore speed follows the number of protection units and the restore point type, not the volume of data. Microsoft publishes median expectations by unit count, and express restore points are materially faster than standard ones. Translating that into a number of hours for your worst realistic scenario is what makes the recovery objective real rather than aspirational.
We set up the defences around the backup itself
Backups are append-only rather than fully immutable, because deletion has to remain possible for offboarding. The compensating controls are a fixed ninety day recovery grace period after offboarding, retention isolated from Purview policies, and multi-admin email notification when a potentially harmful action is taken on the Backup tool. All three get configured deliberately.
We test a restore before anyone calls it protected
Including the timings, because policy activation alone takes on average up to sixty minutes to process and another sixty to create restore points, and initial backups run at roughly fifteen minutes per thousand protection units. Knowing those numbers from your own tenant is worth considerably more than knowing them from documentation.
Six UAE situations where in-tenant backup is the right answer.
An organisation recovering from a large ransomware event
This is the scenario the product was designed around. Microsoft describes the difficulty of copying data at scale from a remote air-gapped location, which can take weeks or months. In-place rollback to an express restore point, across many sites at once, is measured in hours, and that difference is the whole argument.
A regulated firm under data residency expectations
Data never leaves the Microsoft 365 data trust boundary and honours your current data residency locations, with only limited metadata such as tenant and site identifiers going to Azure for billing. For UAE organisations that have had to justify where every copy of their data lives, that removes an argument rather than creating one.
A firm whose exposure is a departing employee, not malware
Deliberate deletion by someone with legitimate access is at least as common as ransomware and far less dramatic, so it is often noticed weeks later. Exchange ten minute restore points cover the prior fifty two weeks, and mail, contacts, calendar and task items can be restored to a new folder in the mailbox rather than overwriting current state.
A business with a single very large SharePoint estate
Because restore speed follows the number of sites rather than the volume of data, an estate with a few enormous sites behaves very differently from one with thousands of small ones. Modelling that against the published performance expectations is the difference between a recovery objective you can meet and one you have written down.
An organisation that has never tested a Microsoft 365 restore
Which is most of them. Retention policies and recycle bins are frequently believed to be backup, and they behave completely differently under a mass encryption event. A tested restore, with a measured duration from your own tenant, converts an assumption into a capability and usually adjusts somebody expectation in the process.
A multi-geo tenant across several countries
Microsoft states that Backup supports sites and user accounts from both the central and satellite locations. For UAE headquartered groups with entities in other regions, that avoids the split arrangement where the head office is protected by one product and the satellite locations are protected by nothing anybody can name.
How UAE organisations protect Microsoft 365 data.
| Feature | Microsoft 365 Backup | Third-party off-tenant backup | Recycle bin and retention only |
|---|---|---|---|
SharePoint, OneDrive and Exchange covered | Yes | Usually more workloads | Partly |
Recovery point interval | 10 minutes | Varies, often daily | Not applicable |
Mass restore speed | Hours | Days to weeks | Not applicable |
Data stays in the Microsoft 365 boundary | Yes | No | Yes |
Copy outside the tenant | No | Yes | No |
Protection against backup overwrite | Append-only | Varies | None |
Retention isolated from Purview policies | Yes | Yes | No |
Restore charges | Free | Varies | Not applicable |
Billing shape | Consumption | Per user or per workload | None |
Useful after a large ransomware event | Yes | Slowly | No |
What is covered, and how each behaves differently.
| Aspect | OneDrive | SharePoint | Exchange Online | |
|---|---|---|---|---|
| Retention period | 1 year | 1 year | 1 year | |
| Standard restore points | 10 minute, for the prior two weeks | 10 minute, for the prior two weeks | 10 minute, for the prior 52 weeks | |
| Longer term points | Roughly daily express, weekly 2 to 52 weeks prior | Roughly daily express, weekly snapshots 2 to 52 weeks prior | Not applicable, 10 minute points run the full year | |
| Backup granularity | OneDrive account | SharePoint site | Exchange user account | |
| Restore granularity | Account, with file version restore coming soon | Site, with file version restore coming soon | Mail, contacts, calendar and task items | |
| Restore location | Same or new URL | Same or new URL | Same or new folder in the mailbox | |
| Restore behaviour | Rollback overwrites content and metadata since that point | Rollback overwrites content and metadata since that point | Restores only modified or deleted items from that point | |
| Express restore points | Yes, and they are the fast path | Yes, and they are the fast path | Not present and not required | |
| Auditability | Actions fully auditable | Actions fully auditable | Actions fully auditable | |
| Geographic residency | Redundant, replicated, honours tenant residency | Redundant, replicated, honours tenant residency | Redundant, replicated, honours tenant residency |
Five steps, and the restore test is not optional.
- 1
Establish what needs protecting and what it will cost to run
All sites and mailboxes, or a selected set. Because billing is consumption based rather than per user, the scope decision has a direct commercial consequence, and we size it against your actual data volumes rather than a headcount. Multi-geo tenants are included, since both central and satellite locations are supported.
- 2
Agree the recovery objectives against published behaviour
Ten minute standard restore points, one year retention, and restore speeds that follow unit count rather than data volume. We translate the published median expectations into hours for your worst realistic scenario, then confirm whether the business accepts that number or needs a different approach for part of the estate.
- 3
Configure protection and the defences around it
Protection policies activated, with the expectation set that activation takes up to sixty minutes to process and another sixty to create restore points, and initial backups run at roughly fifteen minutes per thousand protection units. Multi-admin notification recipients configured, and the ninety day offboarding grace period understood by whoever holds admin rights.
- 4
Write two runbooks and rehearse both
A mass rollback procedure for a destructive event, with the appropriate approval level given that it overwrites everything since the restore point, and a granular procedure for the everyday case. Both rehearsed against real restore points, with the actual elapsed times recorded from your own tenant.
- 5
Decide whether you still need a copy outside the tenant
This product keeps data inside the Microsoft 365 trust boundary, which is a strength for residency and a limitation for anyone whose policy requires an independent copy. That is a deliberate decision to make with a clear head rather than an assumption to discover during an incident, and for some organisations the answer is both.
What organisations ask about Microsoft 365 Backup.
Fifteen questions that make the difference between backup and recovery.
Scope
- All sites and mailboxes, or selected?Both are supported, and it drives consumption.
- Is your tenant multi-geo?Central and satellite locations are both supported.
- What is not covered by this product?The published scope is three workloads.
- Do you also need a copy outside the tenant?A separate decision, not a substitute.
- How much data are you protecting?Consumption billing follows volume.
Recovery objectives
- What recovery point does the business need?Ten minutes is the standard interval.
- How many sites in a worst case?Restore speed follows unit count.
- Is one year of retention enough?That is the published period.
- In place or to a new URL?In place is faster.
- Who approves a full rollback?It overwrites everything since that point.
Operations
- Have you tested a restore?An untested backup is an assumption.
- Who is on the multi-admin notification list?It flags harmful actions on the tool.
- Do you know the 90 day offboarding grace period?It is your last line if backups are deleted.
- Are restore actions audited and reviewed?They are auditable by default.
- Is the runbook written before the incident?Nobody writes a good one during.
The pages around this one.
Ask how many hours a full restore of your SharePoint estate would take.
It is a specific number, it follows from your site count and restore point type, and almost nobody knows theirs. Working it out takes an afternoon and it usually changes the conversation about what protection you need.
Related Services
Explore more solutions that work great with this service
Backup as a Service
M365, endpoint, server backup, immutable
Backup and Restore Audit
We test whether your backups actually restore
Ransomware Protection
Defender XDR and Sentinel-driven ransomware defense
DRaaS
Tested disaster recovery on Azure
Data Backup
Automated backup and data protection
Microsoft 365
Complete Microsoft 365 setup, migration & support
Business Continuity Planning
BCP, RPO/RTO design, and DR runbook authoring
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own