Most organisations using Microsoft 365 assume their data is safe. Microsoft is running the platform, it’s in the cloud, it’s replicated across data centres, surely that’s enough. It isn’t, and the consequences of that assumption tend to surface at the worst possible moment.
This article explains the protection gap Microsoft leaves open, what Veeam Backup for Microsoft 365 does to close it, and what a working implementation looks like.
Why Microsoft Doesn’t Fully Protect Your Data
Microsoft operates under what’s known as the shared responsibility model. It’s a clear division of duties: Microsoft’s job is to keep the Microsoft 365 service running, infrastructure uptime, geo-redundancy, platform-level disaster recovery. Your job is to protect the data that lives inside it.
Microsoft’s own documentation makes this explicit. But the distinction is widely misunderstood, and it’s an expensive misunderstanding to discover after the fact.
The features that often get mistaken for backup, retention policies, the recycle bin, litigation hold, aren’t backup solutions. They’re compliance and availability tools with meaningful limitations:
Exchange Online deletes items from the recycle bin after 14 days by default (extendable to 30). SharePoint’s recycle bin holds items for 93 days. When an employee leaves and their account is removed, their data is deleted after 30 days unless it’s been explicitly preserved elsewhere. Retention policies don’t protect against a malicious insider deleting content with intent. And none of these tools give you an independent, point-in-time copy of your data stored outside Microsoft’s infrastructure.
If your M365 tenant is compromised through ransomware, credential theft, accidental mass deletion, or a misconfigured policy, Microsoft’s native tools may not be enough to recover cleanly. That’s the gap Veeam is built to close.
What Veeam Backup for Microsoft 365 Actually Does
Veeam Backup for Microsoft 365 connects to your M365 tenant through secure Microsoft APIs and creates independent, point-in-time backup copies of your data. These copies are stored entirely under your control, either on-premises or in cloud object storage, completely outside Microsoft’s infrastructure.
That independence is the critical point. If something happens to your tenant, your backup repository is unaffected.
Backup jobs run on a schedule you define, as frequently as every five minutes for high-priority workloads. After the initial full backup, each subsequent job is incremental, only changed items are captured, which keeps storage consumption and backup windows manageable.
Restoration is handled through Veeam’s Explorer tools, which allow granular recovery of individual items without touching anything else. A single email, a specific SharePoint document, a Teams conversation thread, all recoverable without restoring an entire mailbox or site.
Supported Workloads
Veeam Backup for Microsoft 365 covers the core M365 workloads that enterprise environments depend on:
Exchange Online – full backup and recovery of mailboxes including emails, calendar items, and contacts. Granular restore means you can recover a single email from three months ago without affecting anything else in the mailbox.
SharePoint Online – site collections, document libraries, lists, and all associated content. Restore at the item, library, or full-site level depending on what’s needed.
OneDrive for Business – all files and folder structures for every protected user. Particularly important for managing off-boarding scenarios where account deletion would otherwise take files with it.
Microsoft Teams – conversations, channel files, and associated content. Teams data is distributed across Exchange, SharePoint, and other components; Veeam captures it holistically rather than requiring separate job configuration for each underlying service.
Each workload can be protected independently or as part of a unified backup policy covering your entire tenant.
Recovery Scenarios
Backup is only worth discussing in terms of what it recovers from. These are the scenarios that come up most often in enterprise environments:
Ransomware – Modern ransomware increasingly targets cloud collaboration platforms. An attacker with valid credentials, obtained through phishing or credential stuffing, can encrypt SharePoint libraries, corrupt OneDrive files, and delete mailbox data at scale. Because Veeam’s backup repository is independent of your M365 tenant, a clean restore point is available even if the entire tenant is compromised. Veeam also supports immutability on compatible object storage targets, meaning backup data can’t be overwritten or deleted for a defined period, a specific defence against ransomware that targets backup infrastructure itself.
Accidental deletion – The most common cause of data loss in M365 environments isn’t attack, it’s user error. A SharePoint site deleted by an administrator. A contract removed from a shared drive. An email thread gone before anyone realised it was needed for a legal matter. Veeam’s granular restore handles these without requiring a full recovery operation; you find the item, restore it, done.
Malicious insiders – A departing employee with the access and intent to cause damage can delete or exfiltrate significant volumes of data before anyone intervenes. Veeam’s point-in-time copies allow recovery to a state before the damage occurred.
Off-boarding – When a user account is removed from M365, their data starts a countdown to permanent deletion. Veeam allows that data to be retained indefinitely, independent of any active licence, making it accessible for audit, legal hold, or knowledge transfer purposes long after the account is gone.
Compliance and legal hold – When regulators or legal teams need access to specific communications or documents, a searchable backup repository is considerably more efficient than navigating eDiscovery workflows in a live environment. Veeam’s Explorer tools support rapid search and export across backed-up workloads without touching live systems.
Implementation
Veeam Backup for Microsoft 365 is deployed as a software application, typically on a Windows server, physical or virtual, within your environment or hosted by a managed service provider.
At a high level, the implementation process runs as follows:
- Deploy the Veeam server – Install on Windows Server 2016 or later with adequate resources (at minimum 4 CPU cores and 8GB RAM for smaller deployments). The installer handles prerequisites including .NET Framework and SQL Server Express.
- Connect your M365 tenant – Veeam registers an Azure Active Directory application and authenticates with your tenant using delegated or application-level permissions. This is the connection through which all backup jobs operate.
- Configure your backup repository – Choose where backed-up data will be stored, on-premises storage, a NAS device, or cloud object storage such as Azure Blob, Amazon S3, or a compatible alternative. For immutability, select an object storage target that supports object lock. Nexstor’s S3-compatible storage infrastructure is a common choice for UK-based organisations with data residency requirements.
- Create and schedule backup jobs – Define which workloads and users to protect, how frequently backups should run, and what retention policy applies. Incremental backups after the initial full run keep ongoing storage requirements predictable.
- Validate – Run a test restore before you need a real one. Confirm that recovery works as expected across each workload and that your team knows the procedure. A backup that’s never been tested is an assumption, not a guarantee.
For organisations that prefer not to run this in-house, Nexstor deploys and manages Veeam Backup for Microsoft 365 as part of a broader managed backup service, removing the operational overhead while keeping recovery firmly under your control when it matters.
Nexstor is a Veeam Platinum Partner specialising in backup architecture and managed data protection for enterprise environments. If you’d like to discuss your M365 backup position, get in touch.
Speak to one of our experts, book your exploratory meeting below today.