Skip to content

Commit 2aceb36

Browse files
authored
Merge branch 'main' into camillepack-ai
2 parents 7f33ac0 + 166b703 commit 2aceb36

13 files changed

Lines changed: 167 additions & 74 deletions

microsoft-365/backup/backup-overview.md

Lines changed: 45 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -71,9 +71,9 @@ To summarize, applications built on top of the Microsoft 365 Backup Storage plat
7171

7272
Microsoft 365 Backup provides ultra-fast backup and restore capabilities by creating backups within the protected services’ data boundaries.
7373

74-
Microsoft 365 Backup not only provides uniquely fast recovery from common business continuity and disaster recovery (BCDR) scenarios like ransomware or accidental/malicious employee content overwrite/deletion. More BCDR scenario protections are also built directly into the service. For example, OneDrive, SharePoint, and Exchange Online have a proprietary architecture design for resiliency with replicated copies of customer data to failover to live active copies seamlessly without the need for end customer intervention.
74+
Microsoft 365 Backup not only provides uniquely fast recovery from common business continuity and disaster recovery (BCDR) scenarios like ransomware or accidental or malicious employee content overwrite or deletion. More BCDR scenario protections are also built directly into the service. For example, OneDrive, SharePoint, and Exchange Online have a proprietary architecture design for resiliency with replicated copies of customer data to failover to live active copies seamlessly without the need for end customer intervention.
7575

76-
Our backups are protected from malicious overwrites because OneDrive, SharePoint, and Exchange use Append-Only backup storage. This means that SharePoint can only add new content blobs and can never change old ones until they're permanently deleted. The Exchange items are backed up in an immutable manner and can't be accessed by a client process (such as Outlook, OWA, or MFCMAPI). This process ensures that items can't be changed after an initial save, protecting against attackers that try to corrupt old versions. For more information about the built-in service and data resiliency, see [SharePoint and OneDrive data resiliency in Microsoft 365](/compliance/assurance/assurance-sharepoint-onedrive-data-resiliency) and [Exchange Online data resiliency in Microsoft 365](/compliance/assurance/assurance-exchange-data-resiliency).
76+
Our backups are protected from malicious overwrites because OneDrive, SharePoint, and Exchange use Append-Only backup storage. This means that SharePoint can only add new content blobs and can never change old ones until they're permanently deleted. The Exchange items are backed up in a similar append-only manner and can't be accessed by a client process (such as Outlook, OWA, or MFCMAPI). This process ensures that items can't be changed after an initial save, protecting against attackers that try to corrupt old versions. For more information about the built-in service and data resiliency, see [SharePoint and OneDrive data resiliency in Microsoft 365](/compliance/assurance/assurance-sharepoint-onedrive-data-resiliency) and [Exchange Online data resiliency in Microsoft 365](/compliance/assurance/assurance-exchange-data-resiliency).
7777

7878
Key architectural takeaways:
7979

@@ -96,6 +96,7 @@ Restore points are physically created in the service as soon as the policy is co
9696
#### Restoration performance
9797

9898
Restoration performance correlates with your recovery time objective, or the time it takes for you to restore a healthy state of your data and recover from a data destruction event.
99+
99100
For full OneDrive account and SharePoint site restores, the fastest recovery happens when choosing in-place restore rather a new URL restore. Additionally, choosing one of the recommended express restore points presented in the restore workflow user interface yields the quickest recovery results.
100101

101102
All restore points and restores to new URLs are relatively fast, but same URL restores using a recommended express restore point will typically yield better results. The Exchange Online restore workflow doesn't have or require the "faster" restore points.
@@ -110,22 +111,61 @@ The following table summarizes expected performance for a normally distributed t
110111
|1,000+ |Up to 250 protection units per hour |4 hours |
111112
|1,000+|Up to 250 protection units/hour<br>Up to 2 TB/hour* |250+ protection units/hour<br>Up to 2 TB/hour* |
112113

113-
<sup>Restore performance notes:</sup>
114+
<sup>**Important Restore performance notes:**</sup>
114115

115116
<sup>*Single protection unit OneDrive and SharePoint restores using express restore points can take on average between 10 minutes and 120 minutes, depending on site size.</sup> <sup>For mailboxes, restore times typically fall in the 200 - 300 item/minute range.</sup>
116117

117-
<sup>*1,000+ protection unit restore speeds published here are based on internal benchmarking where SharePoint sites have an average of 12GB of stored content per site, Exchange Online mailboxes have an average of 26K items and an aggregate size of 10 GB. Those bulk recoveries use the in-place restore option, which is typical for large scale attack recovery scenarios. Actual times will depend on the number and size of the items in each site/mailbox.</sup>
118+
<sup>*1,000+ protection unit restore speeds published here are based on internal benchmarking where SharePoint sites have an average of 12GB of stored content per site, Exchange Online mailboxes have an average of 26K items and an aggregate size of 10 GB. Those bulk recoveries use the in-place restore option, which is typical for large scale attack recovery scenarios. Actual times will depend on the number and size of the items in each site/mailbox.</sup>
118119

119120
## Pay-as-you-go billing
120121

121122
Microsoft 365 Backup is a pay-as-you-go offering that charges based on consumption, unlike traditional user-based licenses.
122123

123124
## Integrated partner solutions
124125

125-
We partner with many independent software vendors (ISVs) to provide differentiated versions of their applications integrated with the Microsoft 365 Backup Storage platform—all providing the same underlying performance value proposition for your Microsoft 365 data.
126+
We partner with many independent software publishers to provide differentiated versions of their applications integrated with the Microsoft 365 Backup Storage platform—all providing the same underlying performance value proposition for your Microsoft 365 data.
126127

127128
For a partner application, operation of the Microsoft 365 Backup tool will be managed and paid for entirely through the partner's application. Those applications have the ability to provide a single pane of glass for all of your data estates that require backups, and they might provide more enhanced experiences or workflows.
128129

129130
## Multi-geo environments
130131

131132
Microsoft 365 Backup supports the backup of sites and user accounts from both the central and satellite locations.
133+
134+
## Append-only vs. immutable storage overview
135+
136+
### Key points
137+
138+
1. Immutability is formally defined as storage that can't be altered, deleted, or overwritten for a specified period of time.
139+
140+
2. Microsoft 365 Backup follows that definition except for disallowing deletion. Backup uses append-only storage to prevent nondeletion modifications or alterations of existing restore point data. This protects against service or malware overwrites of the backup data.
141+
142+
3. Deletion of the backups isn't blocked, giving customers the option to offboard if needed or desired. There are a couple of defenses against undesired deletions built into the tool to approximate full immutability without some of the related drawbacks (for example, lack of GDPR control). These additional features include:
143+
144+
a. A fixed 90-day existing backup recovery [grace period](/microsoft-365/backup/backup-offboarding), similar to a soft-delete recycle bin within the Backup tool, that allows the customer to recover their backups up to 90 days after offboarding.
145+
146+
b. Retention and deletion policies (for example, from Purview) don't affect the backup retention period, which remains fully isolated from those policies.
147+
148+
c. A multi-admin email notification feature (coming later this year) that will automatically notify a preset group of admins if a potentially harmful action is taken on the Backup tool.
149+
150+
### Deeper storage architectural Look
151+
152+
Microsoft 365 Backup Storage is built on top of standard OneDrive and SharePoint infrastructure; and on top of standard Exchange Online infrastructure. Given that, Microsoft 365 Backup Storage inherits some useful implementation benefits.
153+
154+
One of those benefits is built in append-only storage of the backups.
155+
156+
#### OneDrive SharePoint content modification protection
157+
158+
The service isn't capable of modifying existing copies of the backups because content backups are stored on append-only Azure blobs. Read more about [append-only resiliency](/compliance/assurance/assurance-sharepoint-onedrive-data-resiliency). As a result, our service can only create new copies of the primary data in the backups, aligning to a new restore point corresponding to a new point in time. This is at the core of our append-only functionality.
159+
160+
#### OneDrive SharePoint metadata modification protection
161+
162+
Metadata for OneDrive and SharePoint is stored in Azure SQL databases. The Microsoft 365 Backup tool uses a combination of the built-in Azure SQL point-in-time restore functionality and Azure Blob, to which serialized copies of the SQL DBs are periodically snapshotted.
163+
164+
In both cases, modifications to the database result in new and nonmodifiable point in time copies of the data. Once copied to blob, the immutability explanation from the prior section applies to those Blob-stored DB copies as well. Read more about [OneDrive and SharePoint metadata resiliency](/compliance/assurance/assurance-sharepoint-onedrive-data-resiliency).
165+
166+
#### Exchange Online item modification protection
167+
168+
Exchange Online Backup technology creates point-in-time copies of modified and deleted mailbox items. These backup copies, once created, aren't modifiable by the service. A new copy is taken based on changes to the primary data at scheduled restore point frequency targets.
169+
170+
Review the [Microsoft 365 service terms](https://www.microsoft.com/licensing/terms/product/ForOnlineServices/all).
171+

microsoft-365/backup/backup-restore-data.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -239,7 +239,6 @@ Microsoft 365 Backup supports the backup and restoration of any site and user ac
239239
> After a multi-geo move, a OneDrive account and SharePoint site will only be able to restore to the weekly restore points until an enhancement is deployed (enhancement coming soon).
240240
241241
## Considerations when using restore
242-
243242
- OneDrive and Sharepoint
244243

245244
- Site search is case-sensitive and is a prefix-type search.
@@ -273,7 +272,7 @@ Microsoft 365 Backup supports the backup and restoration of any site and user ac
273272
- If the parent folder of an item has been deleted, the item will be restored to a newly created folder named *Recovered Items YYYY-MM-DD, HH:MM*.
274273

275274
- All
276-
275+
- Restore session history is retained for 366 days.
277276
- Abusive restore actions aren't permitted. You should limit restores for testing purposes to no more than twice a month per protection unit. Restores for real recovery purposes aren't limited.
278277

279278
- The restore point frequency dictates the points in time from which you can recover a prior state of your data. Restore points start being generated when you create the backup policy for a given OneDrive account, SharePoint Site, or Exchange Online mailbox. For Exchange Online, restore points are available for 10 minutes for the entire year. For OneDrive and SharePoint, the available restore points are available for 10 minutes for up to 2 weeks prior, and weekly for 2 to 52 weeks prior. Based on the defined and currently invariable backup frequency setting previously described, the following example highlights what is possible.

microsoft-365/backup/backup-view-edit-policies.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,13 @@ A policy contains details of what data (SharePoint sites, Exchange mailboxes, an
2626

2727
You can create more than one backup policy for each product (SharePoint, Exchange, and OneDrive) with a limit of 100 policies per product. This allows you to segregate your data by logical partitions such as department, geography, and so on for ease of management and administration. Note that any SharePoint site, Exchange mailbox, or OneDrive account can be part of one backup policy only.
2828

29+
> [!NOTE]
30+
> You can also use PowerShell cmdlets to perform these operations by following these steps:
31+
> 1. Go to the [Microsoft 365 Backup Storage Graph APIs](/graph/api/backuprestoreroot-post-exchangeprotectionpolicies) documentation for the specific action you want to perform—for example, creating a SharePoint policy.
32+
> 2. Scroll to the **Example request** section and select the **PowerShell** tab.
33+
> 3. Install the Microsoft.Graph.BackupRestore module as shown in the example.
34+
> 4. Run the provided PowerShell command in an Admin PowerShell session to execute the desired action.
35+
2936
Select the **SharePoint**, **Exchange**, or **OneDrive** tab for steps to create a backup policy for that product.
3037

3138
# [SharePoint](#tab/sharepoint)

microsoft-365/commerce/manage-partners.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.reviewer: prlachhw, ramagane
99
audience: Admin
1010
ms.topic: how-to
1111
ms.service: microsoft-365-business
12-
ms.subservice: m365-commerce-marketplace
12+
ms.subservice: m365-commerce-management
1313
ms.localizationpriority: medium
1414
ms.collection:
1515
- Tier1

microsoft-365/enterprise/advanced-data-residency.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ The following workloads are included in ADR. For more information, see:
5555

5656
The Advanced Data Residency ("ADR") add-on is intended for Microsoft 365 enterprise customers who have comprehensive data residency requirements. To be eligible to purchase ADR, customers must meet the following prerequisites:
5757

58-
- The _Tenant_ _Default Geography_ must be one of the countries or regions included in the _Local Region Geography_: Australia, Brazil, Canada, France, Germany, India, Israel, Italy, Japan, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, and United Kingdom.
58+
- The _Tenant_ _Default Geography_ must be one of the countries or regions included in the _Local Region Geography_: Australia, Brazil, Canada, France, Germany, India, Indonesia, Israel, Italy, Japan, Malaysia, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, and United Kingdom.
5959
- Customers must have licenses for one or more of the following products:
6060
- Microsoft 365 F1, F3, E3, or E5 (including SKUs without Microsoft Teams)
6161
- Office 365 F3, E1, E3, or E5 (including SKUs without Microsoft Teams)

microsoft-365/enterprise/m365-dr-overview.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,8 +33,8 @@ In order to promote clarity in the capability descriptions on data residency fun
3333
|Macro Region Geography 1 - EMEA |Data centers in Austria, Finland, France, Ireland, Italy, Netherlands, Poland, Spain, Sweden <br/> <br/> **Note:** For tenants with a default geography of Israel; data can be stored in Macro Region Geography 1 – EMEA or additional datacenters located in their default geography (i.e., Israel). |
3434
|Macro Region Geography 2 - Asia Pacific |Data centers in Australia, Hong Kong Special Administrative Region, Indonesia, Japan, Malaysia, New Zealand, Singapore, South Korea <br/> <br/> **Note:** For tenants with a default geography of Taiwan; data can be stored in Macro Region Geography 2 – Asia Pacific or additional datacenters located in their default geography (i.e., Taiwan). |
3535
|Macro Region Geography 3 - Americas |Data centers in Brazil, Chile, Mexico, United States |
36-
|Local Region Geography |Australia, Brazil, Canada, France, Germany, India, Indonesia, Israel, Italy, Japan, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, United Kingdom |
37-
|Future Local Region Geography | Future planned data center regions: Malaysia, Austria, Chile, Denmark, Greece, Saudi Arabia |
36+
|Local Region Geography |Australia, Brazil, Canada, France, Germany, India, Indonesia, Israel, Italy, Japan, Malaysia, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, United Kingdom |
37+
|Future Local Region Geography | Future planned data center regions: Austria, Chile, Denmark, Greece, Saudi Arabia |
3838
|Geography |_Local Region Geography, Future Local Region Geography_, or _Macro Region Geography_ |
3939
|Satellite Geography |If a customer subscribes to the Multi Geo service, then they can set policy at a user level to store customer data in other Geographies outside of the _Tenant_ _Primary Provisioned Geography_ |
4040
|Microsoft Entra ID |Microsoft Entra ID is the new name for [Azure Active Directory](/entra/fundamentals/new-name) |
@@ -134,9 +134,11 @@ There are three methods for ensuring that the _Tenant_ data location for a parti
134134
| France | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
135135
| Germany | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
136136
| India | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
137+
| Indonesia | M-A | M-A | M-A | M-A | A | A | A | A |
137138
| Israel | M-A | M-A | M-A | M-A | A | A | A | A |
138139
| Italy | M-A | M-A | M-A | M-A | A | A | A | A |
139140
| Japan | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
141+
| Malaysia | M-A | M-A | M-A | M-A | A | A | A | A |
140142
| Mexico | M-A | M-A | M-A | M-A | A | A | A | A |
141143
| New Zealand | M-A | M-A | M-A | M-A | A | A | A | A |
142144
| Norway | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
@@ -171,11 +173,13 @@ The following Regional Geographies can store data at rest.
171173
|France |Paris, Marseille |
172174
|Germany |Frankfurt, Berlin |
173175
|India |Chennai, Mumbai, Pune |
176+
|Indonesia |Jakarta |
174177
|Israel |Tel Aviv |
175178
|Italy |Milan |
176179
|Japan |Osaka, Tokyo |
177180
|South Korea |Busan, Seoul |
178181
|Spain |Madrid |
182+
|Malaysia |Kuala Lumpur |
179183
|Mexico |Queretaro |
180184
|New Zealand |Auckland |
181185
|Norway |Oslo, Stavanger |

microsoft-365/enterprise/o365-data-locations.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ This article helps you to understand how you can determine current data residenc
3737
> The **Taiwan** local data center region launched on November 1, 2024. If your organization requires the migration of your Microsoft 365 customer data to Taiwan, and data residency commitments for Taiwan, see [Advanced Data Residency](advanced-data-residency.md).
3838
3939
> [!NOTE]
40-
> For tenants in Australia, Brazil, Canada, France, Germany, India, Israel, Italy, Japan, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, and United Kingdom, more workloads are available for data residency commitments. For more information, see [Advanced Data Residency](advanced-data-residency.md).
40+
> For tenants in Australia, Brazil, Canada, France, Germany, India, Indonesia, Israel, Italy, Japan, Malaysia, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, and United Kingdom, more workloads are available for data residency commitments. For more information, see [Advanced Data Residency](advanced-data-residency.md).
4141
4242
See the following links to understand how you can determine current data residency and data residency commitments.
4343

0 commit comments

Comments
 (0)