Site icon Microsoft 365 for IT Pros

How Easy is It to Restore Microsoft 365 Tenants After a Catastrophic Attack

Restore Microsoft 365 te.nant with all workloads
Advertisements

Backup of a Single Workload is Straightforward; Restore of a Complete Microsoft 365 Tenant Is Not

It’s over six years since I published an article explaining why Teams is the most difficult Microsoft 365 application to backup. While Teams remains challenging to backup, since then, some important developments have occurred in the Microsoft 365 backup space, including:

Backup or export APIs are still unavailable for many parts of a Microsoft 365 tenant, including apps like Planner and Power BI along with numerous configuration settings spread across workloads. In many respects, backup is driven on a per-workload basis with little attempt to stitch everything together into a cohesive whole.

The Prospect of a Highly Destructive Attack

Which brings me to the big question: if a tenant is attacked in such a way that many configuration details are removed along with data, how long will it take to reconstruct the tenant to a usable state? Of course, the answer is “it depends.” Every attack is different, and the consequences flowing from an attack depend on the actions taken by the attackers.

For the purpose of this discussion, let’s assume that attackers compromise a target tenant and use a highly permissioned app to exfiltrate data (a problem in itself) and then used the same permissions to perform a malicious large-scale deletion of data. I described this scenario in a 2023 article about “wiperware” attacks.

The scenario is not as far-fetched as it might seem. An attacker who compromises a highly privileged application with permissions such as Files.ReadWrite.All, Sites.ReadWrite.All, Mail.ReadWrite, or directory management permissions could potentially destroy large amounts of content and configuration data. For example, given the right permissions, a malicious app could remove every user account, every group, every administrative unit, every registered app, and every conditional access policy while also deleting user mailboxes, OneDrive accounts, and SharePoint Online sites. They might also remove sensitivity label configuration data to complicate recovery operations for encrypted files and messages.

You might hope that alarm bells would sound to make administrators aware of what’s happening, but alarms are often missed, especially during the night.

The real question is not whether recovery is possible. Rather, we should ask how quickly an organization can re-establish a usable tenant once the damage is done. Tenant administrators should consider the answer carefully, and backup vendors should be prepared to explain how their products restore a fully functional tenant rather than simply recover individual workloads.

Handcrafted Recovery

I am unaware of any product that can restore a complete Microsoft 365 tenant. If such a catastrophic event occurred, the only method available today is a handcrafted recovery where administrators rebuild the tenant one workload at a time using whatever data and configuration settings are available.

The priority is Entra ID. User accounts, groups, apps, service principals, and other objects must be restored to allow workload recoveries to proceed. User accounts must be fully provisioned before mailboxes, OneDrive accounts, and other user-associated resources can be reconnected to their owners. Microsoft 365 groups must exist to allow their SharePoint sites and teams to be reconstructed. Getting accounts and groups up and running is a good start, but so much is now stored in Entra ID that the work of reconstruction only begins once the foundation is laid.

Even with a plan in hand, handcrafted recoveries take time. Lots of time. Some recoveries focus on critical accounts and sites in order to get business operations back online. Some focus on complete workloads. Every company is different, and every company has their own priorities when it comes to working their way back to full recovery. Conceivably, an organization might still be recovering some aspects of their tenant several weeks after beginning. The cost and disruption of this effort is horrendous.

The Need for Automated Recovery

Maersk took months to recover from the famous attack against its Windows Server-based on-premises infrastructure in 2017. At the 2025 TEC conference, then Maersk CIO Adam Banks told the story about how they were saved when a system administrator in Nigeria discovered they had a backup of a domain controller that could be used to rebuild Active Directory.

Microsoft 365 tenants are vastly more complex than an Active Directory forest. If organizations are serious about resilience against catastrophic attacks, recovering data is no longer enough. The next challenge for the backup industry is automated reconstruction of a completely functional Microsoft 365 tenant from trustworthy backup data. Claims of a minimal viable restoration are insufficient.

Artificial intelligence could play an important role in that effort by determining recovery dependencies, establishing the correct sequence for workload restoration, and rebuilding the links between interconnected applications like Teams, SharePoint Online, OneDrive, and Exchange Online. AI could also help reconstruct configuration settings based on the surviving data and metadata available after an attack.

The vendor that figures out how to automate end-to-end Microsoft 365 tenant recovery will find a very receptive market. Simply putting data into a few workloads in a Microsoft 365 tenant is no longer enough.


Microsoft 365 for IT Pros is a trusted source of technical insight that helps tenant administrators stay informed and productive. We update the content every month to reflect changes across Microsoft 365, and monthly update #135 is available now. Get your copy from Gumroad.com and stay up to date with the information that matters most for keeping your tenant secure, compliant, and running efficiently.

Exit mobile version