Direct answer: Microsoft 365 backup data can remain within Microsoft's protected-service boundary, live in a backup provider's managed environment, or be written by a compatible product to customer-controlled infrastructure. None of these models is automatically air-gapped, immutable, compliant, or recoverable. Choose by administrator separation, deletion path, residency, restore fidelity, operating ownership, and exit evidence.
Storage Model Decision Matrix
| Dimension | Microsoft native | Provider-managed | Customer-controlled |
|---|---|---|---|
| Data boundary | Microsoft 365 trust boundary. | Provider's documented service architecture. | Customer-selected cloud or on-premises environment. |
| Primary administrator | Microsoft 365 Backup roles and billing administrators. | Provider operations plus assigned customer operators. | Customer infrastructure and backup administrators. |
| Deletion protection | Append-only against alteration; controlled offboarding can delete backup data. | Depends on provider controls and contract. | Depends on configured product, credentials, retention, and storage mode. |
| Residency | Microsoft documents honoring tenant geographic residency. | Provider must identify applicable regions and transfer boundaries. | Customer chooses and operates the region, subject to provider behavior. |
| Operations | Microsoft operates storage and protection service. | Provider operates service infrastructure and storage. | Customer operates capacity, security, upgrades, monitoring, and recovery dependencies. |
| Exit | Native offboarding and deletion process. | Contractual access, export, migration, and deletion process. | Customer controls infrastructure but still needs a portable catalog and restore engine. |
Microsoft-Native Storage
Microsoft states that native Microsoft 365 Backup data remains within the Microsoft 365 trust boundary, honors the geographic locations of current data residency, and uses multiple physically redundant copies. Its current Backup architecture documentation describes append-only storage: existing restore-point data cannot be changed or overwritten. That is meaningful protection against malicious or accidental alteration.
It is not deletion-proof in the strict sense. Microsoft permits intentional offboarding so customers can end the service and delete backup data. Current controls described by Microsoft include a recovery grace period and multi-administrator notifications. Review the offboarding procedure, role assignments, billing-health behavior, and notification recipients in the actual tenant. Do not reduce the architecture to either "fully immutable" or "the same Global Administrator can instantly delete everything."
Provider-Managed Storage
A managed backup provider can establish a separate administrative and service boundary from the Microsoft 365 tenant. That separation may reduce the chance that one compromised tenant identity controls both production and backup, but it introduces provider access, supplier continuity, region, deletion, and exit decisions. Require evidence rather than treating "hosted outside Microsoft" as a complete security claim.
Commercial models differ. Some providers bundle capacity into a per-user price; others charge by protected or retained storage; North Brook Vault uses a published seat, tenant, and retained-storage formula. Compare actual commercial terms rather than assuming provider-managed storage is included or unlimited.
Customer-Controlled Storage
Customer-selected S3, object storage, NAS, SAN, or on-premises infrastructure can provide direct control over region, credentials, retention settings, and capacity. It also transfers responsibility for configuration, encryption, key and credential handling, Object Lock mode, administrative bypass paths, lifecycle rules, replication, time synchronization, catalog/database recovery, upgrades, monitoring, and cost.
Object Lock is one possible control when both the backup software and storage provider support it. S3 compatibility alone does not enable Object Lock, and Object Lock is not a physical air gap. An always-connected on-premises repository can remain vulnerable to compromised administrators, software defects, hardware failure, and local disasters. Apply Microsoft's general shared-responsibility principles: choosing customer infrastructure increases the controls the customer must operate and prove.
Copyable Storage Due-Diligence Checklist
- [ ] Draw the data path: Identify source tenant, application identity, processing services, metadata/catalog, payload storage, and restore destination.
- [ ] Name administrators: Record who can read, restore, change retention, change billing, offboard, delete, rotate credentials, or access support tooling.
- [ ] Verify deletion behavior: Test or document ordinary deletion, policy removal, account termination, unhealthy billing, provider support action, and legal deletion requests.
- [ ] Verify encryption ownership: Record transport, at-rest protection, key owner, rotation, recovery, and support access without assuming customer-managed keys.
- [ ] Record residency: Capture payload, metadata, logs, support access, subprocessors, replication, and restore destination separately.
- [ ] Test failure recovery: Include unavailable storage, unavailable catalog, expired credential, throttled source, partial backup, and alternate restore destination.
- [ ] Prove exit: Record accessible formats, required software, retrieval cost, migration time, deletion evidence, and what happens to historical restore points.
Storage Evidence Record
| Evidence field | Required entry |
|---|---|
| Architecture | [Data-flow diagram version, services, payload and metadata locations] |
| Administrative boundary | [Production, backup, storage, billing, support, and deletion roles] |
| Storage controls | [Encryption, keys, retention, deletion, replication, durability source] |
| Residency | [Payload, metadata, logs, replication, support access; approval owner] |
| Recovery dependencies | [Catalog/database, credentials, software, network, target API] |
| Exit and deletion | [Notice, export or migration, cost, final access, deletion evidence] |
| Last test | [Scenario, date, result, exceptions, approver] |
North Brook Vault Storage Boundary
North Brook Vault uses the provider-managed model. It is managed SaaS: North Brook Vault operates backup infrastructure, payload storage, retention processing, and service-side monitoring. Customers do not select or administer the backend S3 bucket, local file path, NAS, or on-premises destination. North Brook Vault does not offer customer-selected S3, local file, NAS, or on-premises storage.
North Brook Vault does not currently provide native Object Lock configuration or enforcement. Do not represent its storage as Object-Locked, physically air-gapped, customer-key-controlled, or certified unless current approved service documentation expressly supports that statement. Storage architecture, security controls, residency requirements, support access, and contractual deletion or exit terms must be confirmed in the technical review and written proposal.
Storage selection does not change object-level product limits. North Brook Vault does not capture OneDrive file version history; does not restore Teams chat messages, channel messages, or channel structures; does not export PST, PDF, or ZIP packages; does not produce compliance reports; and does not guarantee zero Microsoft Graph throttling. Review the API and object-handler procedure and the operations checklist alongside this storage decision.
Architecture Decision
Select Microsoft-native storage when the Microsoft trust boundary, native workload scope, one-year retention, and offboarding controls satisfy the scenarios. Select provider-managed storage when separate service operation and documented provider controls meet the requirements. Select customer-controlled storage only when direct control justifies the additional engineering and evidence burden. If customer-selected S3 or on-premises storage is mandatory, North Brook Vault is not a product fit.
Review the provider-managed service Discuss a storage architecture consultation Estimate managed storage and retention