How to Backup Microsoft 365 in India — Step-by-Step Setup
The most common mistake Indian businesses make with Microsoft 365 is assuming Microsoft's built-in retention is the same thing as a backup — it isn't. Microsoft's shared responsibility model is explicit that data protection and backup are the customer's job; Microsoft guarantees infrastructure uptime, not recovery from your own accidental deletion, ransomware, or a malicious insider. Here's how to actually set up independent M365 backup.
Steps
Step 1 — Understand what native retention does and doesn't cover: M365's default recycle bin and version history typically cover 30-93 days depending on the item type and any retention policies configured, and only for straightforward accidental deletion within that window. It does not reliably protect against ransomware that encrypts OneDrive/SharePoint files (encryption isn't "deletion", so recycle bin logic doesn't catch it cleanly), permanent deletion past the retention window, or malicious insider/admin actions that also delete retained copies.
Check your actual configured retention windows in the M365 admin centre — defaults vary by licence tier
Ransomware encrypting files in place is the scenario native retention handles worst
Insider risk (a departing employee or compromised admin account) can delete both live and retained copies
Step 2 — Decide what to protect: Exchange, OneDrive, SharePoint, Teams: Most M365 backup gaps are discovered department by department — Exchange mailbox backup gets set up first because email loss is obvious, while OneDrive, SharePoint document libraries and Teams chat/files data (which often holds equally critical business data) get missed. Scope backup across all four from the start rather than adding them reactively after a loss.
Teams data specifically includes files shared in channels and chat history — often overlooked
SharePoint site collections need explicit inclusion, not just the "main" sites
Shared mailboxes and distribution-list-owned resources are commonly missed in scoping
Step 3 — Choose a backup platform and connect via the M365 connector: A dedicated SaaS backup platform (Druva is the authorised option here) connects via Microsoft Graph API with delegated admin permissions — no agent installation needed on individual mailboxes or drives. Review exactly what permissions the connector requests and confirm your security team is comfortable with the scope before authorising.
Review the exact API permission scope requested before authorising the connector
Confirm the backup vendor's data storage region — for Indian data residency, a Mumbai-region option matters
Test the connection with a small pilot group before scoping to the full tenant
Step 4 — Set retention policy independent of Microsoft's: Configure your backup retention to be longer than — and independent of — Microsoft's native settings. This is the point of independent backup: if your M365 retention policy is misconfigured, changed, or a licence downgrade shortens it, your independent backup retention is unaffected because it doesn't rely on Microsoft's policy at all.
Set backup retention based on your actual compliance/legal-hold needs, not Microsoft's default
Long-term archival retention (years, not months) is a common gap independent backup should close
Document why your retention period was chosen — useful for future compliance review
Step 5 — Run the first full backup and verify it completed: Initial full backup of a real tenant takes longer than incremental backups thereafter — plan for this rather than assuming near-instant coverage. Once complete, actively verify (not assume) that mailboxes, drives and sites you expected to see are actually backed up.
First full backup timeline scales with data volume — budget accordingly for a large tenant
Spot-check specific mailboxes/sites against the backup console's inventory, not just a summary count
Set a calendar reminder to re-verify coverage after any org-wide change (new department, acquisition, etc.)
Step 6 — Test a real restore before you need one for real: A backup nobody has tested restoring from is a hope, not a plan. Run a test restore — a single email, a deleted OneDrive file, a whole mailbox — on a schedule, and document how long it actually takes. This is also the number you'll need when someone asks "how fast can we get this back" during a real incident.
Test restore quarterly at minimum, not just once at setup
Time the restore process and document it — this becomes your real recovery-time estimate
Test at least one full-mailbox or full-drive restore, not just single-item restores
Frequently Asked Questions
Doesn't Microsoft already back up our data?
Microsoft protects the infrastructure — replicating data across data centres for uptime and availability — but that is explicitly not the same as protecting you from your own data loss events. Microsoft's Services Agreement places responsibility for backup of your content on you, the customer; this is the industry-standard "shared responsibility model" that applies to every major cloud/SaaS platform, not something unique or unusual to Microsoft.
How does ransomware actually bypass M365's native protection?
Ransomware that gets access to a synced OneDrive or SharePoint folder encrypts the files in place — the files still technically "exist" from Microsoft's point of view, just with unreadable content, and the encrypted (bad) version can even sync and overwrite older good versions depending on version history depth. Independent backup with point-in-time snapshots lets you roll back to a version from before the encryption happened, which native version history has limited depth to guarantee.
Is this required for compliance in India?
DPDP Act 2023 requires "reasonable security safeguards" for personal data, and independent backup is a standard, expected control for demonstrating data resilience — particularly for BFSI, healthcare and any business handling customer personal data at meaningful scale. It is not named explicitly as mandatory line-by-line, but auditors and regulators consistently expect to see it as part of a reasonable security posture.
How much does independent M365 backup typically cost?
Priced per user per year, typically in the low thousands of rupees per user annually depending on scope (mailbox-only vs full Exchange+OneDrive+SharePoint+Teams) and retention length. For most Indian organisations this is a small fraction of the cost of actually losing critical data with no way to recover it — the ROI case is rarely close once a real incident is considered.
WhatsApp +91 98119 98370 for an INR quote with GST invoice, deployment support, and ongoing service from National IT Service.