Table of Contents
Backup of a Single Workload is Straightforward; Restore of a Complete Microsoft 365 Tenant Is Not
It’s over six years since I published an article explaining why Teams is the most difficult Microsoft 365 application to backup. While Teams remains challenging to backup, since then, some important developments have occurred in the Microsoft 365 backup space, including:
- The upcoming retirement of Exchange Web Services (EWS) sometime in 2027. Despite EWS never being intended to act as a backup API, many vendors used EWS to retrieve Exchange mailbox data. Hopefully, everyone has read the tea leaves and has replaced EWS in their products, possibly with a highly-permissioned enterprise app that uses the Graph Mailbox Import-Export API to gain read access to every mailbox in the tenant.
- The provision of the Teams Export API to remove the need to backup Teams compliance records from user mailboxes instead of real Teams message data. I could never understand why so many vendors were able to make claims that this action was a real backup. It wasn’t.
- The entry of Microsoft into the backup market with Microsoft 365 Backup for SharePoint Online and Exchange Online. Some vendors use the backup APIs underneath their user interface. Entra ID also introduced a limited backup capability earlier this year.
- The start of a strategy to address the issue of configuration backups with the arrival of a preview of Unified Tenant Configuration Management (UTCM) in early 2026. It’s not perfect and definitely doesn’t cover everything found in a tenant, but UTCM is a start.
Backup or export APIs are still unavailable for many parts of a Microsoft 365 tenant, including apps like Planner and Power BI along with numerous configuration settings spread across workloads. In many respects, backup is driven on a per-workload basis with little attempt to stitch everything together into a cohesive whole.
The Prospect of a Highly Destructive Attack
Which brings me to the big question: if a tenant is attacked in such a way that many configuration details are removed along with data, how long will it take to reconstruct the tenant to a usable state? Of course, the answer is “it depends.” Every attack is different, and the consequences flowing from an attack depend on the actions taken by the attackers.
For the purpose of this discussion, let’s assume that attackers compromise a target tenant and use a highly permissioned app to exfiltrate data (a problem in itself) and then used the same permissions to perform a malicious large-scale deletion of data. I described this scenario in a 2023 article about “wiperware” attacks.
The scenario is not as far-fetched as it might seem. An attacker who compromises a highly privileged application with permissions such as Files.ReadWrite.All, Sites.ReadWrite.All, Mail.ReadWrite, or directory management permissions could potentially destroy large amounts of content and configuration data. For example, given the right permissions, a malicious app could remove every user account, every group, every administrative unit, every registered app, and every conditional access policy while also deleting user mailboxes, OneDrive accounts, and SharePoint Online sites. They might also remove sensitivity label configuration data to complicate recovery operations for encrypted files and messages.
You might hope that alarm bells would sound to make administrators aware of what’s happening, but alarms are often missed, especially during the night.
The real question is not whether recovery is possible. Rather, we should ask how quickly an organization can re-establish a usable tenant once the damage is done. Tenant administrators should consider the answer carefully, and backup vendors should be prepared to explain how their products restore a fully functional tenant rather than simply recover individual workloads.
Handcrafted Recovery
I am unaware of any product that can restore a complete Microsoft 365 tenant. If such a catastrophic event occurred, the only method available today is a handcrafted recovery where administrators rebuild the tenant one workload at a time using whatever data and configuration settings are available.
The priority is Entra ID. User accounts, groups, apps, service principals, and other objects must be restored to allow workload recoveries to proceed. User accounts must be fully provisioned before mailboxes, OneDrive accounts, and other user-associated resources can be reconnected to their owners. Microsoft 365 groups must exist to allow their SharePoint sites and teams to be reconstructed. Getting accounts and groups up and running is a good start, but so much is now stored in Entra ID that the work of reconstruction only begins once the foundation is laid.
Even with a plan in hand, handcrafted recoveries take time. Lots of time. Some recoveries focus on critical accounts and sites in order to get business operations back online. Some focus on complete workloads. Every company is different, and every company has their own priorities when it comes to working their way back to full recovery. Conceivably, an organization might still be recovering some aspects of their tenant several weeks after beginning. The cost and disruption of this effort is horrendous.
The Need for Automated Recovery
Maersk took months to recover from the famous attack against its Windows Server-based on-premises infrastructure in 2017. At the 2025 TEC conference, then Maersk CIO Adam Banks told the story about how they were saved when a system administrator in Nigeria discovered they had a backup of a domain controller that could be used to rebuild Active Directory.
Microsoft 365 tenants are vastly more complex than an Active Directory forest. If organizations are serious about resilience against catastrophic attacks, recovering data is no longer enough. The next challenge for the backup industry is automated reconstruction of a completely functional Microsoft 365 tenant from trustworthy backup data. Claims of a minimal viable restoration are insufficient.
Artificial intelligence could play an important role in that effort by determining recovery dependencies, establishing the correct sequence for workload restoration, and rebuilding the links between interconnected applications like Teams, SharePoint Online, OneDrive, and Exchange Online. AI could also help reconstruct configuration settings based on the surviving data and metadata available after an attack.
The vendor that figures out how to automate end-to-end Microsoft 365 tenant recovery will find a very receptive market. Simply putting data into a few workloads in a Microsoft 365 tenant is no longer enough.
Microsoft 365 for IT Pros is a trusted source of technical insight that helps tenant administrators stay informed and productive. We update the content every month to reflect changes across Microsoft 365, and monthly update #135 is available now. Get your copy from Gumroad.com and stay up to date with the information that matters most for keeping your tenant secure, compliant, and running efficiently.

