OneDrive Security & Recovery

How to Back Up OneDrive for Business: Admin and Pilot Guide

Updated Aug 21, 20266 min readBy Security Engineering

Direct answer: protect OneDrive by combining the native controls that meet short-term recovery needs with a tested backup when you require a different retention period, administrative boundary, or restore workflow. A synchronized local folder is not backup because deletion, overwrite, and encryption can synchronize in both directions.

Use the Correct OneDrive Timelines

Individual deleted items normally remain in the OneDrive recycle bin for 93 days, subject to Microsoft configuration and administrative actions. Deleted-user OneDrive retention is a different process. When a user account is deleted from Microsoft Entra ID, OneDrive is retained for the period configured in the SharePoint admin center; the default is 30 days. After that configured period, the OneDrive remains in a deleted state for 93 days and can be restored by a SharePoint administrator while that window remains open.

Removing a license is not the same event as deleting the Entra account. Microsoft now documents a separate unlicensed-OneDrive lifecycle and archive behavior. Review OneDrive retention and deletion before writing an offboarding runbook, and use Microsoft's deleted OneDrive restore procedure rather than assuming permanent deletion occurs on day 30.

OneDrive also offers file version history and Files Restore for rolling an account back after mass deletion, overwrite, or corruption in the previous 30 days. Results depend on the available activity, recycle-bin items, and versions. These native controls can be sufficient for some organizations; test them before buying another layer.

OneDrive Recovery and Capture Matrix

RequirementNative pathNorth Brook Vault boundaryPilot proof
Current file contentActive OneDrive, recycle bin, or Files Restore where applicableCaptures current drive-item content in scheduled snapshots; selective drive-item restore is supportedHash, size, MIME type, name, path, and open test
Folder hierarchyRecycle bin or Files Restore for supported eventsCaptures folders and hierarchy; test parent reconstruction and conflictsNested paths and child counts before and after restore
Metadata and timestampsAvailable properties vary by native workflowCaptures current drive-item metadata; restore fidelity must be testedCreated/modified values, identities, and custom requirements
Sharing and permissionsReview current OneDrive sharing state and audit recordsStores separate permission snapshots; do not infer full permission restoration without a pilotDirect grants, links, inherited access, and removed access
Historical file versionsOneDrive version history under the configured version policyNot currently captured by North Brook Vault as file-version historyFail North Brook Vault if historical versions are mandatory
Deleted-user OneDriveConfigured retention followed by the 93-day deleted state; retention policies can alter outcomesRequires a retained snapshot and a supported restore destinationApproved offboarding test with source and target identities
Storage separationMicrosoft-native data remains in Microsoft's service boundaryNorth Brook Vault uses provider-managed storage, not customer local, NAS, file, or S3 storageArchitecture and responsibility review

Admin Procedure

  1. Inventory scope: export licensed, unlicensed, blocked, and deletion-pending users; record OneDrive URLs, ownership, storage used, and business owner.
  2. Define recovery classes: ordinary file recovery, mass rollback, former-employee recovery, legal preservation, and alternate-location recovery.
  3. Inspect native settings: recycle-bin expectations, version-history policy, Purview retention, deleted-user retention, and unlicensed-account handling.
  4. Set RPO and RTO: base frequency and retention on approved business impact, not the product default. The M365 RTO/RPO guide provides a worksheet.
  5. Authorize and preflight: review the application permissions, consent owner, excluded users, service accounts, and conditional-access implications.
  6. Run the initial job: reconcile discovered drives, completed items, item-level errors, downloaded content, and throttling.
  7. Validate incrementals: create, edit, rename, move, permission-change, and delete test items; ensure the next snapshot represents the intended state.
  8. Restore before production: use both original and alternate destinations where supported, then retain the evidence.

Document who controls storage credentials, deletion, encryption, residency, lifecycle, and incident response. North Brook Vault is a managed SaaS service; compare that model in the M365 backup storage guide. It does not currently provide native Object Lock configuration or enforcement.

Seeded Pilot Scenarios

  1. Create a three-level folder tree containing small, large, Office, PDF, and non-ASCII filenames. Record hashes and IDs.
  2. Create a file, capture a snapshot, edit it twice, and prove that only captured snapshot states are recoverable. Do not count OneDrive file-version history as North Brook Vault coverage.
  3. Rename and move a file between folders, then delete it. Test recovery from before and after each change.
  4. Add a direct permission and sharing link, remove one, and compare the permission snapshot and restored result.
  5. Use an approved pilot user to test offboarding, ownership transfer, account deletion, and recovery destination without risking production data.
  6. Force a filename conflict at the target and record overwrite, skip, rename, or failure behavior.

Pass/Fail Evidence Checklist

Product Fit and No-Fit Boundaries

North Brook Vault fits teams that need managed scheduled capture of supported current OneDrive files, folders, content, metadata, and permission snapshots with selective restore for supported drive items. It does not claim continuous capture, OneDrive file-version-history backup, customer-controlled local or S3 storage, native Object Lock, or universal permission fidelity.

Make offboarding a controlled gate, not an automatic license-removal task. Confirm the manager or data owner, ownership transfer, retention and legal-hold status, last successful snapshot, shared-link dependencies, and tested recovery destination before deleting the Entra account. Record the configured deleted-user retention period and the separate unlicensed-account policy in the ticket.

It is a no-fit when historical OneDrive versions, BYO storage, legal-production export, or an untested deleted-user recovery workflow is mandatory. Those requirements need another control or a layered design.

Review OneDrive recovery coverage Discuss a OneDrive recovery consultation Review managed-service pricing