MSP Guide

Microsoft 365 Backup Operations Guide for MSPs

Updated Aug 22, 20268 min readBy Partner Engineering

Direct answer: An MSP should sell Microsoft 365 backup only after defining a repeatable service that separates every tenant, states object-level coverage and exclusions, assigns monitoring and escalation, measures recovery, reconciles billing, and controls offboarding. "Backed up regularly" is not a service description, and a platform console is not a substitute for an operating owner.

Microsoft's shared-responsibility guidance leaves customer data, identities, and access management with the customer in SaaS. An MSP can operate delegated processes, but the client still needs to approve business requirements and customer-side access. The MSP must clearly distinguish its responsibilities from Microsoft's, the backup provider's, and the client's.

Copyable Service Definition

Service fieldClient-specific entryEvidence
Protected scope[Tenants, workloads, object types, included/excluded identities and sites]Approved scope register and platform reconciliation.
Backup operation[Configured schedule, retention, latest usable point definition]Configuration and job history.
Recovery service[Supported objects, source dates, destinations, conflict handling]Current capability matrix and representative restore results.
Client objective[RPO/RTO target by scenario]Business approval and measured test.
Monitoring[Review owner, cadence, stale-point threshold, escalation]Ticket trail and latest review.
Request handling[Authorized requesters, approvers, identity verification, priority]Request and approval record.
Commercial terms[Seats, tenants, storage/retention, minimums, pass-through costs]Monthly reconciliation and client agreement.
Offboarding[Stop date, retained-data decision, access, deletion, final billing]Approved exit record.

Tenant Onboarding Procedure

  1. Qualify the requirement: Use the policy template to identify required workloads, objects, retention, recovery destinations, and business owners.
  2. Create the tenant record: Record legal client name, Microsoft tenant ID, technical contact, security contact, billing owner, data-residency decision, and escalation contacts.
  3. Authorize access: Record the application identity, requested Microsoft Graph permissions, consenting administrator, credential owner, grant date, and revocation path.
  4. Run preflight: Reconcile each required handler as passed, failed, or unsupported. Resolve failures or obtain written risk acceptance before production.
  5. Configure scope and policy: Record selected identities, sites, workloads, schedule, retention, exclusions, and deleted-user handling. Do not assume a departed identity remains billable or protected; document the selected product and contract behavior.
  6. Establish the first usable point: Review item-level errors and completion state. A created job does not establish protection.
  7. Test recovery: Restore a representative supported object to an approved destination and record fidelity and elapsed time.
  8. Obtain acceptance: The client owner approves scope, known gaps, measured results, operating contacts, and commercial inputs.

Tenant Isolation Test

North Brook Vault publicly describes tenant-scoped credentials, jobs, snapshots, schedules, and policies. Treat that as a capability to validate, not permission to skip access testing.

Operating RACI

ActivityClientMSPBackup provider
Approve requirements and riskAccountableConsulted/facilitatesSupplies capability evidence
Grant tenant consentAccountable/responsibleCoordinates if authorizedPublishes required permissions
Operate service infrastructureInformedInformed/escalatesAccountable/responsible
Review tenant outcomesAccountable for accepted riskResponsible under service definitionProvides job state and support
Approve a restoreAccountableVerifies request and operatesOperates supported service workflow
Accept restored dataAccountable/responsibleRecords resultAddresses service defects

Monitoring and Escalation Checklist

Microsoft Graph throttling is expected platform behavior, not proof of a provider outage. Microsoft's current guidance requires clients to handle HTTP 429 responses and honor retry instructions. No MSP tier should promise zero throttling.

  1. [ ] Review latest usable point for every contracted scope, not just the most recent job start.
  2. [ ] Review partial failures by handler, object, permission, throttling, deleted source, and unsupported type.
  3. [ ] Open a ticket with tenant, affected scope, business objective, error, owner, due time, and escalation state.
  4. [ ] Notify the client when the latest usable point exceeds the agreed notification condition. Do not invent an SLA not in the service agreement.
  5. [ ] Close with evidence showing a new usable point or an approved exception.

Billing Reconciliation

Reconcile billing from platform and contract evidence, not an assumed license count. North Brook Vault's public formula includes protected seats, additional tenants, monthly new backup data, retention, included allowances, and a monthly minimum. Use the pricing calculator for the approved formula, then record any MSP service margin or client-facing packaging separately.

Billing period[Start/end date and invoice reference]
Protected seats[Count, evidence source, changes, departed-user decision]
Tenants[Active tenant count and onboarding/offboarding dates]
Storage/retention inputs[Monthly new data, retention, estimate versus actual source]
MSP service components[Monitoring, support, restore labor, included/excluded work]
Approved variance[Difference, cause, client notification, owner]

Client Review Evidence

A QBR should show service decisions, not claim compliance. Include protected scope, latest usable points, failed or stale scopes, restore requests, test results, open exceptions, seat/storage changes, and planned client changes. North Brook Vault provides job state and history but does not provide a compliance report. The MSP must build any client review from validated operational records and must not label it a certification.

North Brook Vault Coverage and Limits

North Brook Vault's managed Microsoft 365 backup for MSPs uses provider-managed infrastructure and storage, tenant-scoped operations, service-side monitoring, retention policies, and selective restore handlers for supported Exchange, OneDrive, SharePoint, and Teams objects. The MSP remains responsible for reviewing tenant outcomes, client access, request authorization, escalation, service packaging, billing reconciliation, and recovery acceptance.

North Brook Vault does not offer customer-selected S3 or on-premises deployment, native Object Lock enforcement, OneDrive version-history capture, PST/PDF/ZIP export, compliance reports, or a zero-throttling guarantee. Teams chats, channel messages, and channel structures are not restorable. Set service targets only after using the RTO/RPO worksheet in a representative restore test, and operate production with the backup operations checklist.

Service Launch Decision

Launch a client only after onboarding acceptance, isolation checks, a usable recovery point, a representative restore, named monitors, billing inputs, and offboarding ownership are complete. Sell the tested service boundary, not an unlimited "Microsoft 365 backup" promise.

Review the MSP backup service Discuss an MSP recovery consultation