You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: microsoft-365/backup/backup-overview.md
+45-5Lines changed: 45 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -71,9 +71,9 @@ To summarize, applications built on top of the Microsoft 365 Backup Storage plat
71
71
72
72
Microsoft 365 Backup provides ultra-fast backup and restore capabilities by creating backups within the protected services’ data boundaries.
73
73
74
-
Microsoft 365 Backup not only provides uniquely fast recovery from common business continuity and disaster recovery (BCDR) scenarios like ransomware or accidental/malicious employee content overwrite/deletion. More BCDR scenario protections are also built directly into the service. For example, OneDrive, SharePoint, and Exchange Online have a proprietary architecture design for resiliency with replicated copies of customer data to failover to live active copies seamlessly without the need for end customer intervention.
74
+
Microsoft 365 Backup not only provides uniquely fast recovery from common business continuity and disaster recovery (BCDR) scenarios like ransomware or accidental or malicious employee content overwrite or deletion. More BCDR scenario protections are also built directly into the service. For example, OneDrive, SharePoint, and Exchange Online have a proprietary architecture design for resiliency with replicated copies of customer data to failover to live active copies seamlessly without the need for end customer intervention.
75
75
76
-
Our backups are protected from malicious overwrites because OneDrive, SharePoint, and Exchange use Append-Only backup storage. This means that SharePoint can only add new content blobs and can never change old ones until they're permanently deleted. The Exchange items are backed up in an immutable manner and can't be accessed by a client process (such as Outlook, OWA, or MFCMAPI). This process ensures that items can't be changed after an initial save, protecting against attackers that try to corrupt old versions. For more information about the built-in service and data resiliency, see [SharePoint and OneDrive data resiliency in Microsoft 365](/compliance/assurance/assurance-sharepoint-onedrive-data-resiliency) and [Exchange Online data resiliency in Microsoft 365](/compliance/assurance/assurance-exchange-data-resiliency).
76
+
Our backups are protected from malicious overwrites because OneDrive, SharePoint, and Exchange use Append-Only backup storage. This means that SharePoint can only add new content blobs and can never change old ones until they're permanently deleted. The Exchange items are backed up in a similar append-only manner and can't be accessed by a client process (such as Outlook, OWA, or MFCMAPI). This process ensures that items can't be changed after an initial save, protecting against attackers that try to corrupt old versions. For more information about the built-in service and data resiliency, see [SharePoint and OneDrive data resiliency in Microsoft 365](/compliance/assurance/assurance-sharepoint-onedrive-data-resiliency) and [Exchange Online data resiliency in Microsoft 365](/compliance/assurance/assurance-exchange-data-resiliency).
77
77
78
78
Key architectural takeaways:
79
79
@@ -96,6 +96,7 @@ Restore points are physically created in the service as soon as the policy is co
96
96
#### Restoration performance
97
97
98
98
Restoration performance correlates with your recovery time objective, or the time it takes for you to restore a healthy state of your data and recover from a data destruction event.
99
+
99
100
For full OneDrive account and SharePoint site restores, the fastest recovery happens when choosing in-place restore rather a new URL restore. Additionally, choosing one of the recommended express restore points presented in the restore workflow user interface yields the quickest recovery results.
100
101
101
102
All restore points and restores to new URLs are relatively fast, but same URL restores using a recommended express restore point will typically yield better results. The Exchange Online restore workflow doesn't have or require the "faster" restore points.
@@ -110,22 +111,61 @@ The following table summarizes expected performance for a normally distributed t
110
111
|1,000+ |Up to 250 protection units per hour |4 hours |
111
112
|1,000+|Up to 250 protection units/hour<br>Up to 2 TB/hour*|250+ protection units/hour<br>Up to 2 TB/hour*|
<sup>*Single protection unit OneDrive and SharePoint restores using express restore points can take on average between 10 minutes and 120 minutes, depending on site size.</sup> <sup>For mailboxes, restore times typically fall in the 200 - 300 item/minute range.</sup>
116
117
117
-
<sup>*1,000+ protection unit restore speeds published here are based on internal benchmarking where SharePoint sites have an average of 12GB of stored content per site, Exchange Online mailboxes have an average of 26K items and an aggregate size of 10 GB. Those bulk recoveries use the in-place restore option, which is typical for large scale attack recovery scenarios. Actual times will depend on the number and size of the items in each site/mailbox.</sup>
118
+
<sup>*1,000+ protection unit restore speeds published here are based on internal benchmarking where SharePoint sites have an average of 12GB of stored content per site, Exchange Online mailboxes have an average of 26K items and an aggregate size of 10 GB. Those bulk recoveries use the in-place restore option, which is typical for large scale attack recovery scenarios. Actual times will depend on the number and size of the items in each site/mailbox.</sup>
118
119
119
120
## Pay-as-you-go billing
120
121
121
122
Microsoft 365 Backup is a pay-as-you-go offering that charges based on consumption, unlike traditional user-based licenses.
122
123
123
124
## Integrated partner solutions
124
125
125
-
We partner with many independent software vendors (ISVs) to provide differentiated versions of their applications integrated with the Microsoft 365 Backup Storage platform—all providing the same underlying performance value proposition for your Microsoft 365 data.
126
+
We partner with many independent software publishers to provide differentiated versions of their applications integrated with the Microsoft 365 Backup Storage platform—all providing the same underlying performance value proposition for your Microsoft 365 data.
126
127
127
128
For a partner application, operation of the Microsoft 365 Backup tool will be managed and paid for entirely through the partner's application. Those applications have the ability to provide a single pane of glass for all of your data estates that require backups, and they might provide more enhanced experiences or workflows.
128
129
129
130
## Multi-geo environments
130
131
131
132
Microsoft 365 Backup supports the backup of sites and user accounts from both the central and satellite locations.
133
+
134
+
## Append-only vs. immutable storage overview
135
+
136
+
### Key points
137
+
138
+
1. Immutability is formally defined as storage that can't be altered, deleted, or overwritten for a specified period of time.
139
+
140
+
2. Microsoft 365 Backup follows that definition except for disallowing deletion. Backup uses append-only storage to prevent nondeletion modifications or alterations of existing restore point data. This protects against service or malware overwrites of the backup data.
141
+
142
+
3. Deletion of the backups isn't blocked, giving customers the option to offboard if needed or desired. There are a couple of defenses against undesired deletions built into the tool to approximate full immutability without some of the related drawbacks (for example, lack of GDPR control). These additional features include:
143
+
144
+
a. A fixed 90-day existing backup recovery [grace period](/microsoft-365/backup/backup-offboarding), similar to a soft-delete recycle bin within the Backup tool, that allows the customer to recover their backups up to 90 days after offboarding.
145
+
146
+
b. Retention and deletion policies (for example, from Purview) don't affect the backup retention period, which remains fully isolated from those policies.
147
+
148
+
c. A multi-admin email notification feature (coming later this year) that will automatically notify a preset group of admins if a potentially harmful action is taken on the Backup tool.
149
+
150
+
### Deeper storage architectural Look
151
+
152
+
Microsoft 365 Backup Storage is built on top of standard OneDrive and SharePoint infrastructure; and on top of standard Exchange Online infrastructure. Given that, Microsoft 365 Backup Storage inherits some useful implementation benefits.
153
+
154
+
One of those benefits is built in append-only storage of the backups.
The service isn't capable of modifying existing copies of the backups because content backups are stored on append-only Azure blobs. Read more about [append-only resiliency](/compliance/assurance/assurance-sharepoint-onedrive-data-resiliency). As a result, our service can only create new copies of the primary data in the backups, aligning to a new restore point corresponding to a new point in time. This is at the core of our append-only functionality.
Metadata for OneDrive and SharePoint is stored in Azure SQL databases. The Microsoft 365 Backup tool uses a combination of the built-in Azure SQL point-in-time restore functionality and Azure Blob, to which serialized copies of the SQL DBs are periodically snapshotted.
163
+
164
+
In both cases, modifications to the database result in new and nonmodifiable point in time copies of the data. Once copied to blob, the immutability explanation from the prior section applies to those Blob-stored DB copies as well. Read more about [OneDrive and SharePoint metadata resiliency](/compliance/assurance/assurance-sharepoint-onedrive-data-resiliency).
165
+
166
+
#### Exchange Online item modification protection
167
+
168
+
Exchange Online Backup technology creates point-in-time copies of modified and deleted mailbox items. These backup copies, once created, aren't modifiable by the service. A new copy is taken based on changes to the primary data at scheduled restore point frequency targets.
169
+
170
+
Review the [Microsoft 365 service terms](https://www.microsoft.com/licensing/terms/product/ForOnlineServices/all).
Copy file name to clipboardExpand all lines: microsoft-365/backup/backup-restore-data.md
+1-2Lines changed: 1 addition & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -239,7 +239,6 @@ Microsoft 365 Backup supports the backup and restoration of any site and user ac
239
239
> After a multi-geo move, a OneDrive account and SharePoint site will only be able to restore to the weekly restore points until an enhancement is deployed (enhancement coming soon).
240
240
241
241
## Considerations when using restore
242
-
243
242
- OneDrive and Sharepoint
244
243
245
244
- Site search is case-sensitive and is a prefix-type search.
@@ -273,7 +272,7 @@ Microsoft 365 Backup supports the backup and restoration of any site and user ac
273
272
- If the parent folder of an item has been deleted, the item will be restored to a newly created folder named *Recovered Items YYYY-MM-DD, HH:MM*.
274
273
275
274
- All
276
-
275
+
- Restore session history is retained for 366 days.
277
276
- Abusive restore actions aren't permitted. You should limit restores for testing purposes to no more than twice a month per protection unit. Restores for real recovery purposes aren't limited.
278
277
279
278
- The restore point frequency dictates the points in time from which you can recover a prior state of your data. Restore points start being generated when you create the backup policy for a given OneDrive account, SharePoint Site, or Exchange Online mailbox. For Exchange Online, restore points are available for 10 minutes for the entire year. For OneDrive and SharePoint, the available restore points are available for 10 minutes for up to 2 weeks prior, and weekly for 2 to 52 weeks prior. Based on the defined and currently invariable backup frequency setting previously described, the following example highlights what is possible.
Copy file name to clipboardExpand all lines: microsoft-365/backup/backup-view-edit-policies.md
+7Lines changed: 7 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -26,6 +26,13 @@ A policy contains details of what data (SharePoint sites, Exchange mailboxes, an
26
26
27
27
You can create more than one backup policy for each product (SharePoint, Exchange, and OneDrive) with a limit of 100 policies per product. This allows you to segregate your data by logical partitions such as department, geography, and so on for ease of management and administration. Note that any SharePoint site, Exchange mailbox, or OneDrive account can be part of one backup policy only.
28
28
29
+
> [!NOTE]
30
+
> You can also use PowerShell cmdlets to perform these operations by following these steps:
31
+
> 1. Go to the [Microsoft 365 Backup Storage Graph APIs](/graph/api/backuprestoreroot-post-exchangeprotectionpolicies) documentation for the specific action you want to perform—for example, creating a SharePoint policy.
32
+
> 2. Scroll to the **Example request** section and select the **PowerShell** tab.
33
+
> 3. Install the Microsoft.Graph.BackupRestore module as shown in the example.
34
+
> 4. Run the provided PowerShell command in an Admin PowerShell session to execute the desired action.
35
+
29
36
Select the **SharePoint**, **Exchange**, or **OneDrive** tab for steps to create a backup policy for that product.
Copy file name to clipboardExpand all lines: microsoft-365/enterprise/advanced-data-residency.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -55,7 +55,7 @@ The following workloads are included in ADR. For more information, see:
55
55
56
56
The Advanced Data Residency ("ADR") add-on is intended for Microsoft 365 enterprise customers who have comprehensive data residency requirements. To be eligible to purchase ADR, customers must meet the following prerequisites:
57
57
58
-
- The _Tenant__Default Geography_ must be one of the countries or regions included in the _Local Region Geography_: Australia, Brazil, Canada, France, Germany, India, Israel, Italy, Japan, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, and United Kingdom.
58
+
- The _Tenant__Default Geography_ must be one of the countries or regions included in the _Local Region Geography_: Australia, Brazil, Canada, France, Germany, India, Indonesia, Israel, Italy, Japan, Malaysia, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, and United Kingdom.
59
59
- Customers must have licenses for one or more of the following products:
60
60
- Microsoft 365 F1, F3, E3, or E5 (including SKUs without Microsoft Teams)
61
61
- Office 365 F3, E1, E3, or E5 (including SKUs without Microsoft Teams)
Copy file name to clipboardExpand all lines: microsoft-365/enterprise/m365-dr-overview.md
+6-2Lines changed: 6 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,8 +33,8 @@ In order to promote clarity in the capability descriptions on data residency fun
33
33
|Macro Region Geography 1 - EMEA |Data centers in Austria, Finland, France, Ireland, Italy, Netherlands, Poland, Spain, Sweden <br/> <br/> **Note:** For tenants with a default geography of Israel; data can be stored in Macro Region Geography 1 – EMEA or additional datacenters located in their default geography (i.e., Israel). |
34
34
|Macro Region Geography 2 - Asia Pacific |Data centers in Australia, Hong Kong Special Administrative Region, Indonesia, Japan, Malaysia, New Zealand, Singapore, South Korea <br/> <br/> **Note:** For tenants with a default geography of Taiwan; data can be stored in Macro Region Geography 2 – Asia Pacific or additional datacenters located in their default geography (i.e., Taiwan). |
35
35
|Macro Region Geography 3 - Americas |Data centers in Brazil, Chile, Mexico, United States |
36
-
|Local Region Geography |Australia, Brazil, Canada, France, Germany, India, Indonesia, Israel, Italy, Japan, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, United Kingdom |
37
-
|Future Local Region Geography | Future planned data center regions: Malaysia, Austria, Chile, Denmark, Greece, Saudi Arabia |
36
+
|Local Region Geography |Australia, Brazil, Canada, France, Germany, India, Indonesia, Israel, Italy, Japan, Malaysia, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, United Kingdom |
37
+
|Future Local Region Geography | Future planned data center regions: Austria, Chile, Denmark, Greece, Saudi Arabia |
38
38
|Geography |_Local Region Geography, Future Local Region Geography_, or _Macro Region Geography_|
39
39
|Satellite Geography |If a customer subscribes to the Multi Geo service, then they can set policy at a user level to store customer data in other Geographies outside of the _Tenant__Primary Provisioned Geography_|
40
40
|Microsoft Entra ID |Microsoft Entra ID is the new name for [Azure Active Directory](/entra/fundamentals/new-name)|
@@ -134,9 +134,11 @@ There are three methods for ensuring that the _Tenant_ data location for a parti
134
134
| France | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
135
135
| Germany | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
136
136
| India | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
137
+
| Indonesia | M-A | M-A | M-A | M-A | A | A | A | A |
137
138
| Israel | M-A | M-A | M-A | M-A | A | A | A | A |
138
139
| Italy | M-A | M-A | M-A | M-A | A | A | A | A |
139
140
| Japan | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
141
+
| Malaysia | M-A | M-A | M-A | M-A | A | A | A | A |
140
142
| Mexico | M-A | M-A | M-A | M-A | A | A | A | A |
141
143
| New Zealand | M-A | M-A | M-A | M-A | A | A | A | A |
142
144
| Norway | P-M-A | P-M-A | P-M-A | P-M-A | A | A | A | A |
@@ -171,11 +173,13 @@ The following Regional Geographies can store data at rest.
Copy file name to clipboardExpand all lines: microsoft-365/enterprise/o365-data-locations.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,7 +37,7 @@ This article helps you to understand how you can determine current data residenc
37
37
> The **Taiwan** local data center region launched on November 1, 2024. If your organization requires the migration of your Microsoft 365 customer data to Taiwan, and data residency commitments for Taiwan, see [Advanced Data Residency](advanced-data-residency.md).
38
38
39
39
> [!NOTE]
40
-
> For tenants in Australia, Brazil, Canada, France, Germany, India, Israel, Italy, Japan, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, and United Kingdom, more workloads are available for data residency commitments. For more information, see [Advanced Data Residency](advanced-data-residency.md).
40
+
> For tenants in Australia, Brazil, Canada, France, Germany, India, Indonesia, Israel, Italy, Japan, Malaysia, Mexico, New Zealand, Norway, Poland, Qatar, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, United Arab Emirates, and United Kingdom, more workloads are available for data residency commitments. For more information, see [Advanced Data Residency](advanced-data-residency.md).
41
41
42
42
See the following links to understand how you can determine current data residency and data residency commitments.
0 commit comments