The Top 4 Concerns You Need to Address for Foolproof Office 365 Backup

Post Date: 04/06/2016
feature image

cloud2“Once I’m in the cloud I’m safe. Microsoft guarantees the fidelity of my data and ensures that I always have a backup should I need to restore content or if there is a catastrophic failure in their system. Because of this, I don’t need to worry about backing up my content.”

While there is some truth to this statement, it also highlights several of the biggest concerns and gaps in the native Office 365 data protection solutions available to subscribers. Although the data that is stored in the cloud is protected, this does not mean that Microsoft will be able to restore content in a way that meets your needs or internal service level agreements. If you are deploying a hybrid environment, you will need to ensure that content across your entire SharePoint deployment is protected whether it lives in the cloud or your own data center. While the specifics discussed here are focused on your cloud deployment, utilizing these best practices throughout your environment can help to ensure a winning backup strategy across any environment. This article will cover four key facets of protecting your data to help you ensure business continuity in the cloud.

1.      Set Your Goals for Office 365 Data Protection

Any time you discuss Office 365 data protection, you need to approach the problem with two primary goals in mind: Recovery Point Objective (RPO) and Recovery Time Objective (RTO). This allows you to approach the problem with a clear understanding of your responsibilities to the organization. Once those are established, you can look at the native solution provided in SharePoint Online as well as the gaps within it that you need to fill.

Recovery Point Objective (RPO)

Understanding how your RPO – the maximum targeted timeframe in which data can be restored from a backup – will affect backup plans is the first place to start. It includes the plan for the frequency of backups as well as your ability to recover individual components. Having this information available gives you a clear way to plan for backups. It defines your commitment to the organization as well as protects you from unreasonable requests. Some good questions to ask when first defining your organizations RPO (or, more likely, building new backup plans for your organization):

  1. How recent does your backup need to be? Having multiple tiers of data is a best practice, as not all of your content is created equal. Classifying data according to importance to the business allows you to create RPOs that ensure all of your content is protected while allowing business critical information to be restored at a more recent point in time.
  2. How granular does your backup need to be? While you are determining how frequently you need your content to be backed up, you should also consider the granularity with which you need to restore that content. Ensuring that business critical documents can be restored individually without affecting the rest of your system can save you a lot of headaches.

Recovery Time Objective (RTO)

Just like planning your RPO, ensuring that you have an RTO – or the amount of time in which content must be restored defined by a service level agreement – in place will protect not only your business but you as well. Creating predefined timeframes for restoration of content helps you refine your recovery points as well as classify the data you are backing up. Having a tiered system in place helps ensure your end users that their business critical information will always be recoverable to a specific point in time. Using your RTO in conjunction with your RPOs can help you drive specific SLAs for content in your environment. Keep the following questions in mind when setting up your RTOs:

  1. How critical is the information that I need to back up?
  2. How quickly will business users need their content restored?
  3. How much content can I restore inside of a specific time frame?

2.      Understand Native Office 365 Data Protection Solutions

Before you can address any gaps in native data protection capabilities, you must first understand what Microsoft offers to you as an Office 365 subscriber. Let’s examine how Microsoft protects your data as well as how it restores that content. Depending on where it is stored, Microsoft guarantees that data can be restored for different amounts of time and at different levels – and it only keeps backup data for 14 days. As an example, data that is stored in a user’s OneDrive for Business site is only available for 90 days after it has been moved to the recycling bin. Additionally, only the most current version of that file is retained. The same applies to SharePoint Online site content (although versions are able to be restored from the recycle bin). You are still facing a hard limit on the restore time. Perhaps more importantly, if you need to recover content that has been permanently deleted, there is no way to recover just the item that you need. Microsoft restores your data at the site collection level as an in place restoration. This means any changes, updates, or additions to that site collection that occurred since the site collection was backed up will be lost. The RTO Microsoft provides to restore content is 48 hours. This is problematic if you have tighter internal SLAs. Even if your SLAs align with Microsoft’s promise, you’re still dealing with a restoration of content that will wipe out changes in your environment made since the last 14-hour RPO. In most cases, this won’t be acceptable to your users or organization.

3.      Address the Gaps in Native Office 365 Data Protection

Once you’ve defined your organization’s RPOs and RTOs, as well as examined how those requirements fit into the native SharePoint backup solution, you can begin to fill in the gaps.

  1. Recovery Timeframe: The first is the timeframe in which data can be restored. If you are not able to restore user content quickly enough business can grind to a halt and all eyes will be on you as the administrator. Ensuring that you can restore content on demand as quickly as possible is the first step in protecting not only your businesses content, but also yourself.
  2. Content Fidelity: The next issue is restoring content with full fidelity. It may not be enough to restore the data to its original location without version history and metadata. If you are using a data classification system, it is also vital that this information is restored along with the content to ensure you can meet SLAs.

Granularity is arguably the most important piece of any Office 365 data protection plan. Restoring content down to the item level ensures a minimal disruption to business processes. Combining this with data classification ensures that the most business critical content gets the level of protection it requires. Including these tiers in your SLAs can help you ease the burden on IT teams in the event of a restoration.

4.      Ensure Your Plan Covers All the Bases

Understanding the limitations of SharePoint’s native backup solution as well as your specific business needs helps determine an Office 365 data protection plan that is both sensible and executable. Make sure that you have the following as part of your plan to ensure your own sanity and keep business running smoothly. 1. Define your data tiers

  • How sensitive is your content?
  • How business critical is your content?
  • How business critical do your end users think the content is?

2. Define your Service Level Agreements

  • How quickly can you feasibly restore the content?
  • How much content needs to be restored?
  • Is there an easier way to recover the data?

3. Define your Recovery Point Objective and Recovery Time Objective

  • How long is the data available to be restored?
  • Do you have different recovery points for different levels of content?

4. Fill the native gaps

  • Do you have a plan to address the gaps in the native backup?
  • How do we restore individual items?
  • How do we restore to a new location?
  • How do we keep long term backups?

What’s Next?

Whether you’re fully in the cloud or utilizing a hybrid environment, AvePoint is well prepared to help you fill all of these gaps with fast, flexible, and intelligent Office 365 data protection solutions. As you plan your journey to the cloud, be sure to check out AvePoint’s Cloud Arcade for more helpful tips on how to manage, migrate, and protect Office 365! You can also learn more about Office 365 reliability by registering for our upcoming webinar, AvePoint’s Cloud Arcade Presents: How to Win the Office 365 Management Game, airing at 2:00PM ET on Wednesday, April 13.

Webinar 3 Facebook

Subscribe to our blog