Microsoft’s Reality Check
Scrutiny of an organization’s cyber recovery capabilities is vital. In the event of a ransomware attack that compromises the SaaS data housed within the Microsoft cloud ecosystem—data essential for the business—the speed at which operations can resume is often based on notions that may not be accurate. If anyone claims, “It’s all good. Microsoft has my back with its all-encompassing native retention and recovery features,” a significant reality check is in order. With dynamic business tools such as M365 and Entra ID coupled with robust backend infrastructure like Azure, Microsoft contributes significantly to the SaaS landscape.
Shared Responsibility Model with a Twist
Nonetheless, both IT departments and MSPs must recognize that Redmond adheres to the same shared responsibility model common among major SaaS providers. During a cyberattack, the responsibility for recovery is divided between what the cloud provider manages and what is solely the subscriber’s duty. MSPs are additionally constrained by the need to fulfill strict SLAs, collaborate with clients’ selected providers or tools, and balance their staffing and profitability.
Microsoft ensures its services remain operational following an incident but does not guarantee the restoration of data to a pre-established good state before the event. That responsibility has always rested with the customer, and preparing for it before an issue arises is exponentially better than improvising amidst the aftermath.
Recognizing the Cyber Recovery Gap
“There’s a widespread misunderstanding regarding Microsoft’s liabilities, as distinct from the service they offer,” explains Brent Torre, GM of cyber resilience. Microsoft’s inherent tools, he clarifies, tackle issues like accidental short-term deletions and elements of data governance. They do not constitute a backup solution and fail to protect against ransomware or restore data. “Microsoft is explicit that for any SaaS application such as Microsoft 365, platform applications like SQL Server, or VMs in Azure, the responsibility for the information in that service, including devices, accounts, and identities, lies entirely with the customer,” he insists.
“If you are breached and the attacker begins deleting data, Microsoft bears no responsibility for that.”
Evolution of Cyberattacks
The divide between availability and real cyber recovery is often misconceived, and it has significantly widened over recent years. There are three main factors contributing to this divide. The first factor is the transformation of cyberattacks. Traditional cyberattacks have shifted from breaching defensive measures to exploiting human vulnerabilities because entering through the front door with a stolen pass is less complicated than squeezing through a broken window. Identity has emerged as the primary attack vector.
As a Service Models and Compliance Chaos
Another contributing element is the ongoing trend of shifting workloads to infrastructure and platform as a service (IaaS and PaaS) models, which shows no signs of slowing down. Organizations typically maintain some functions on-premises, place some in SaaS applications, and utilize others within cloud environments. However, they frequently fail to protect and manage everything to the same standard of quality. Data is backed up in various locations, but whether it is all equally recoverable in the event of a breach remains an area of vulnerability that is often misunderstood.
The ‘as a service’ model is popular, yet it becomes the weak link during ransomware incidents.
The third aspect of the issue is the increasing number of compliance mandates requiring cyber resilience alongside proper backup and recovery protocols, for which many organizations are ill-equipped. Collectively, these challenges allow criminals the opportunity to inflict extensive damage to data, business processes, and compliance standings in the void between attack and the restoration of SaaS functionality.
Independent Backup: Your Cyber Safety Net
Considering that Microsoft’s inherent retention and recovery features are not structured to provide true cyber resilience, preparing to restore the business to its pre-attack state is imperative.
Maintaining a Strong Backup Strategy
“At Kaseya, we consistently advise keeping a backup of your data independently of the primary environment it’s running on,” suggests Torre. “This should be an immutable backup that you can restore from even if the Microsoft, Google, or Salesforce ecosystem is down.” This level of protection is ideally provided through a dedicated cloud-to-cloud backup solution kept outside the main SaaS tenant, which he asserts is becoming increasingly incorporated into cyber insurance and compliance frameworks.
Rapid Recovery: The Real MVP
By extracting copies of frequently targeted data from the Microsoft tenant for offshore storage in a third-party data center, organizations can ensure that if SaaS credentials are compromised, crucial assets remain protected from attack. Subsequently, restoration can reintegrate what is necessary back into the SaaS environment, even if the original tenant has been wiped out.
“In fact, some individuals find it quicker to establish a new shell and rebuild it than to attempt regaining access to a compromised tenant,” Torre remarks. “Whether you are an internal IT technician working late or an MSP striving to uphold your SLAs and maintain profitability, you need a solution that is incredibly straightforward and that you can trust for successful recovery. Both IT departments and MSPs should be on the lookout for an exceptionally user-friendly solution. Disaster recovery isn’t their sole responsibility.”
Selecting the Right Platform
A strong platform, according to Torre, goes beyond merely ensuring recovery; it should also maintain high standards for the hygiene of the cyber resilience environment without the need for constant human oversight. It must guarantee that Microsoft 365 and Entra ID are restored in one cohesive workflow so identities and the associated data come back online correctly instead of in separate phases.
Datto: Bridging the Cyber Recovery Gap
Datto, a cybersecurity and data protection company owned by Kaseya, offers Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID, which collectively aim to bridge the void between availability and recovery by storing secure copies of tenant data in the Datto Cloud, separate from the Microsoft infrastructure. This ensures that if a production tenant is compromised, the recovery point remains intact.
“With our M365 backup, we are protecting one million users globally,” Torre asserts. “Many organizations have come to rely on our capability to protect and recover their data. We offer a trusted recovery platform emphasizing ease of use, not just for M365 but also for Azure and Entra ID.”
IT leaders and MSP operatives need to acknowledge that a ransomware incident, or any cyber emergency, is more a question of when than if. Recovery is paramount, eclipsing the importance of protection because protection is inevitably going to falter at some stage, and conventional data backup strategies alone are insufficient. Preparing for disaster is inadequate; the organization must also be structured to deal with the fallout. This entails ensuring as much as possible that the Microsoft framework can be rapidly restored, down to the last byte of data.
This capability is foundational for modern business processes and operations. Microsoft monitors over 4,000 identity attacks every second and examines 38 million identity risk alerts daily—no organization is exempt from the target list. When an attack occurs, the clock on restoration is already counting down, and any delay in fully reinstating IT operations and critical environments to their pre-attack condition can determine the difference between survival and collapse, with profits, regulatory compliance, and reputation all contingent on the outcome.
Safeguarding data with specialized cyber resilience platforms that allow for quick and clean recovery is how organizations rise to that challenge. MSPs aiming to close the gap can initiate their efforts using the Datto MSP Buyer’s Guide to Microsoft Entra ID Backup Sponsored by Datto.
Conclusion
Backup: It’s Not Just for the Anxious!
Organizations that blindly rely on Microsoft’s cloud services without an effective backup strategy are akin to Geordies hitting the Toon without a coat. Think you’re protected? It’s time for a reality check, mate! A chasm wider than the Tyne Bridge separates availability from recovery. Plan ahead, or you’ll find yourself mired in cyber distress.