Backup and Recovery for Charleston Businesses
A file from last Tuesday, a mailbox, or an entire server, brought back by a restore that has already been rehearsed.
What managed backup covers
Copies of your Microsoft 365 data, your servers, your workstations and your websites are taken on a schedule and kept separately from the systems they came from. The copies, the monitoring that watches them and the response when something changes all run inside one Microsoft tenant. Recovery is the other half of the job, and it is the half that is proven rather than assumed.
What is protected
Microsoft 365 data
Mail, calendars, OneDrive, SharePoint and Teams content, copied by Veeam for Microsoft 365 into Azure and held on their own retention rather than the tenant’s.
Servers
Image-based copies through Veeam or Acronis, so a server is rebuilt as it was configured rather than reinstalled from scratch and pieced back together.
Workstations
The laptop or desktop somebody actually works on, covered by the same image-based tooling, including the documents that never made it to a shared drive.
Straight to cloud storage
N-able Cove and Axcient where the copy should go directly to cloud storage, with no appliance on the floor to keep running.
Websites
WordPress files and database captured together by UpdraftPlus and versioned, so a site returns to a state it is known to have worked in.
Whole-site recovery
The order several systems come back in when more than one is involved at once, written down and rehearsed as a sequence.
Backup and security are one practice here
-
Copies that never leave the cloud they came from
Microsoft 365 data is copied into Azure. Both ends sit in the same cloud, so the copy does not travel over your office connection and how fast a restore runs is not governed by the line into the building.
-
One tenant for backup, detection and response
The backup platforms, Microsoft Defender and Microsoft Sentinel all report into the same Microsoft tenant. Watching the copies, spotting a change on an endpoint and acting on it happen where the data already is, rather than in three consoles that each know a third of the story.
-
Microsoft Sentinel, operated rather than purchased
Sentinel is a SIEM. It collects logs from the tenant, the endpoints and the backup jobs into one timeline and runs detection rules against them. Standing one up and keeping its rules current is continuous work, and it is the part a firm this size is least likely to have staffed.
-
A restore point chosen from records
Because endpoint activity, sign-in history and backup job history land in the same place, picking which copy to bring back is a question answered from a timeline rather than estimated.
Three things happen, in this order
Decide what is protected
Every system is listed and given a schedule and a retention period. Anything not on the list is not protected, so the list itself is a deliverable and it is reviewed as systems change.
Run the copies and check them
Jobs run on their schedule and each result is read. A job that did not finish gets looked at that day rather than becoming a line in a monthly report.
Rehearse the restore
Restores are performed on a schedule and the time each one takes is recorded, so a full recovery has been done before the day it is needed.
What is actually hard about this
-
A deletion window is not a backup
Microsoft 365 holds deleted mail and files for a period set on the tenant and then removes them permanently. That window covers a mistake noticed quickly. A separate copy on its own retention is what brings a mailbox back after the window has closed.
-
Recovering a file and recovering a machine are different jobs
One document comes back in minutes from a file-level copy. A server comes back from an image, in an order: the operating system, the roles it ran, the data, then everything that pointed at it. Which one is being asked for changes what happens next.
-
A backup that has never been restored is an assumption
A job reporting success proves a copy was written. It does not prove the copy opens, that the database inside it is consistent, or that anyone knows the sequence to bring it back. Proving those is a separate exercise with its own schedule.
-
A second copy is only a second copy if it is somewhere else
A copy sitting on the machine it came from, or on the same network share, fails with whatever the original fails with. Copies are kept off the machine and off the network they were taken from, which is the property that makes the second one worth having.
-
How far back you can go is a decision, not a default
Retention is set per system, because the useful history for a finance server and for a laptop are not the same length. It is written down with the schedule, so the answer to how far back a system goes is a number somebody chose rather than whatever the software shipped with.
-
Some questions the platforms’ own reports do not answer
Where a stock report does not cover what you need to know, the check is written to run against your own Microsoft tenant and report from there. That is engineering against your environment, and it is how a question specific to one business gets a specific answer.
-
The first full restore is the one nobody has timed
How long a whole server takes to come back is only knowable by doing it, and it varies with the size of the image and where it is going. Doing it once in advance turns that into a figure you can plan around.
Who this is built for
Offices running Microsoft 365
Where the working files live in SharePoint and OneDrive and there is no server holding a second copy of them.
Businesses with a server on site
Where one machine runs the application the day depends on, and holding its image is what makes that a restore rather than a rebuild.
Firms whose website takes enquiries
Where the site and its database have to go back together, at the same version, for the site to work at all.
Questions
Microsoft holds deleted items for a window set on your tenant and then removes them. That covers something noticed the same week. Bringing a mailbox back after that window needs a separate copy kept on its own retention.
It depends on the size of the image and the hardware it is going back to, which is why the figure is measured on your systems during a rehearsal rather than quoted from a brochure.
A backup is the copy. Disaster recovery is the order several systems are brought back in, and the rehearsal that proves the order works.
Yes. Mail, calendars, OneDrive, SharePoint sites and Teams content are all covered, because the working files in most offices now sit in SharePoint and OneDrive rather than on a server.
As far back as the retention set for that system, which is agreed per system rather than applied as one number to everything.
Veeam and Acronis for servers and workstations, Veeam for Microsoft 365 for tenant data, N-able Cove and Axcient where a copy should go straight to cloud storage, and UpdraftPlus for WordPress sites. More than one, because an estate with a server in it and an estate that is entirely in Microsoft 365 do not want the same tool.
Microsoft 365 data is copied into Azure, so both ends of that copy are in the same cloud. Server and workstation images go to cloud storage as well, which is what keeps a restore from depending on a device sitting in the same building as the original.
Sentinel collects logs from the tenant, the endpoints and the backup jobs into one timeline. That is what makes choosing a restore point a decision based on records of what happened and when, rather than an estimate.
On a schedule agreed per system, with the result and the elapsed time recorded so the number is known in advance.
Talk to a technician
Tell us what you are running and you will get a straight answer on what it takes to protect it and how quickly it comes back.