Most Microsoft 365 backup conversations start in the wrong place — comparing vendors before agreeing what the product has to do. These are the criteria that separate a real backup from a retention policy.
First: Microsoft does not back up your tenant
This is the single most common misconception, and Microsoft is explicit about it. The shared responsibility model puts service availability with Microsoft and data responsibility with you. Recycle bins, retention policies and litigation hold are not backup — they are retention features with time limits and gaps.
The practical consequences: items deleted beyond the retention window are unrecoverable, a compromised admin account can purge data, and there is no point-in-time restore of a whole mailbox or site to a known-good state.
The criteria that actually matter
1. Immutability
Can backup data be altered or deleted inside its retention window — by anyone, including an administrator with valid credentials? If yes, ransomware and insider action both defeat it. Immutability is the difference between a copy and a control.
2. Air-gap
Is there a copy unreachable from the production network? Attackers target backup infrastructure first, precisely because it determines whether you have to pay.
3. Restore granularity
Can you restore a single mail item, a single file version, and an entire site — without restoring everything around it? Coarse restore granularity turns a small incident into a large outage.
4. Coverage across the tenant
Exchange Online, SharePoint, OneDrive and Teams. Teams is the usual gap: its data is scattered across SharePoint, OneDrive and a chat substrate, and partial coverage is easy to mistake for full coverage.
5. Retention that matches obligation, not convenience
Regional and sector requirements may demand retention well beyond the default. Check what long retention costs — the answer is often where pricing models diverge sharply.
6. Restore testing
Can you rehearse a restore without disrupting production? A backup that has never been restored is a hypothesis, not a control. This is the criterion most often skipped and most often regretted.
7. Licensing model
Per-user, per-mailbox or per-GB — the model matters more than the headline rate. Estates with many light users and a few heavy ones price very differently under each.
Where Vembu fits
Vembu BDRSuite covers Microsoft 365 alongside virtual machines and physical servers from a single console, which is the practical argument for most mid-sized estates: one product and one operational routine rather than a separate tool for the tenant.
For a dedicated ransomware posture, BDRShield adds immutable, air-gapped storage with zero-trust recovery.
We deployed this across a 14-clinic hospital group in under six weeks, with recovery rehearsed rather than assumed — the case study covers it. Our fuller argument is in why Vembu BDRSuite wins on M365 protection.
How to evaluate without a bake-off
Score candidates against the seven criteria above using your own estate’s numbers — user count, data volume, retention obligation, recovery time objective. Most shortlists resolve themselves once retention cost and restore granularity are priced honestly.
If you would rather test than model, we will run a proof-of-concept against your tenant in our Dubai lab. Start with a free EUC assessment.
Related: Backup and cyber recovery · Healthcare