Direct answer: A usable Microsoft 365 backup policy must name the protected objects, business owner, latest acceptable recovery point, recovery acceptance criteria, responsible operators, storage and deletion boundaries, test procedure, and evidence location. A policy that says only "back up Microsoft 365 daily" is not actionable and cannot show that recovery is possible.
This template is a planning aid, not legal, regulatory, certification, or audit advice. Records, privacy, security, and legal owners must approve requirements. Microsoft documents separate behavior for Purview retention and the optional Microsoft 365 Backup product; neither should be treated as interchangeable with the other or with an independent backup service.
Copyable Policy Statements
Purpose. [Organization] will maintain tested recovery paths for approved Microsoft 365 business scenarios. Controls may include workload-native recovery, Microsoft Purview retention or holds, Microsoft 365 Backup, and an independent backup service. Selection will be based on documented requirements and demonstrated recovery, not workload-level marketing labels.
Scope. The policy applies only to the tenants, workloads, identities, sites, drives, mailboxes, and object types listed in the scope register. An object is not considered protected until authorization succeeds, a usable recovery point is recorded, monitoring ownership is assigned, and the required restore test passes.
Recovery objectives. Business owners approve maximum acceptable data loss and recovery time per scenario. Effective RPO is measured from the incident to the latest verified usable recovery point. Effective RTO is measured from authorized recovery declaration until documented acceptance criteria pass.
Testing. Tests use only documented restore capabilities and representative objects. A successful backup job is not a successful recovery test. Failed or partially faithful restores remain open exceptions until accepted by the business owner or remediated.
Review. The policy is reviewed [frequency] and after material changes to licensing, permissions, workloads, providers, retention, administrators, storage architecture, or incident experience.
Scope Register
| Tenant/workload | Objects in scope | Business owner | Recovery scenario | Control | Known exclusion |
|---|---|---|---|---|---|
| [Tenant / Exchange] | [User/shared mailboxes; messages, contacts, calendars] | [Name/role] | [Deleted item or mailbox scenario] | [Native, retention, backup] | [Unsupported metadata or destination] |
| [Tenant / OneDrive] | [Named drives, current files, folders, permissions] | [Name/role] | [Deleted or overwritten item] | [Native, retention, backup] | [Version history if not captured] |
| [Tenant / SharePoint] | [Sites, libraries, lists, pages, required metadata] | [Name/role] | [Item or site corruption] | [Native, retention, backup] | [Untested structure or permission fidelity] |
| [Tenant / Teams] | [Members, files, messages, channels as separately specified] | [Name/role] | [Team or message recovery] | [Purview, native, backup] | [Unsupported message/channel restore] |
Responsibility Assignment
| Activity | Accountable | Responsible | Consulted | Evidence |
|---|---|---|---|---|
| Approve scope and objectives | Business owner | IT service owner | Security, legal, records | Signed scope register |
| Authorize tenant access | Customer identity owner | Authorized tenant administrator | Security | Consent and permission record |
| Operate service infrastructure | Contracted provider | Provider operations | Customer service owner | Service description and job history |
| Review failed or stale jobs | Customer service owner | [Named customer/MSP operator] | Provider support | Ticket, decision, latest usable point |
| Authorize and accept recovery | Business owner | Recovery operator | Security and affected users | Request, approval, acceptance record |
Minimum Control Requirements
- [ ] Authorization: Record application permissions, administrator consent, credential owner, review date, and revocation procedure.
- [ ] Scope: Reconcile required objects against the product's object-level backup and restore support.
- [ ] Schedule and recovery point: Record configured frequency, job completion behavior, monitoring owner, and how a usable recovery point is identified.
- [ ] Retention: State the approved period, deletion authority, exceptions, legal-hold interaction, and end-of-service handling.
- [ ] Storage: Record provider, region or residency decision, encryption responsibility, administrative boundary, deletion controls, and exit path. Use the storage decision guide.
- [ ] Recovery: State supported source and destination, overwrite or conflict behavior, expected metadata, and acceptance checks.
- [ ] Incident integration: Name recovery triggers, approver, communications owner, escalation path, and evidence location.
Recovery Test Procedure
- Select a representative object and recovery point that are within documented product support.
- Open a test request with scenario, owner, destination, approvals, and acceptance criteria.
- Record the latest available recovery point before starting; do not infer it from schedule alone.
- Start the restore and record timestamps for authorization, initiation, provider completion, and business acceptance.
- Verify content, hierarchy, permissions, identifiers, timestamps, links, and any conflict handling required by the scenario.
- Record skipped or changed objects and decide whether to remediate, accept, or change the requirement. Use the RTO/RPO worksheet for measurement.
Evidence and Exception Log
| Field | Required entry |
|---|---|
| Test identity | [Ticket, tenant, workload, object, operator, approver] |
| Recovery-point evidence | [Snapshot/recovery-point identifier and timestamp] |
| Timing | [Declared, authorized, started, completed, accepted] |
| Fidelity | [Content, hierarchy, metadata, permissions, identifiers, unsupported fields] |
| Exception | [Gap, impact, owner, due date, compensating control, risk acceptance] |
| Approval | [Business owner and security review date] |
North Brook Vault Coverage and Limits
North Brook Vault is managed SaaS. North Brook Vault operates service infrastructure, provider-managed storage, scheduled jobs, retention processing, and service-side monitoring. Supported backup handlers cover selected Exchange, OneDrive, SharePoint, and Teams objects, while selective restore varies by object type. Teams messages and channel structures are not restorable; OneDrive file version history is not captured. North Brook Vault does not provide customer-selected S3 or on-premises deployment, native Object Lock enforcement, PST/PDF/ZIP export, compliance reports, a zero-throttling guarantee, or a universal RPO/RTO commitment. Confirm the required handler, destination, and fidelity in a pilot before marking a scope row compliant with this policy.
For implementation sequencing, apply the backup operations checklist after this policy is approved.
Adoption Decision
Approve the policy only when every in-scope scenario has an owner, a mapped control, measurable acceptance criteria, and either a successful test or a documented exception. The policy should describe reality, not the intended future state.
Map policy to service coverage Discuss a policy consultation Estimate the managed-service cost