Direct answer: An MSP should sell Microsoft 365 backup only after defining a repeatable service that separates every tenant, states object-level coverage and exclusions, assigns monitoring and escalation, measures recovery, reconciles billing, and controls offboarding. "Backed up regularly" is not a service description, and a platform console is not a substitute for an operating owner.
Microsoft's shared-responsibility guidance leaves customer data, identities, and access management with the customer in SaaS. An MSP can operate delegated processes, but the client still needs to approve business requirements and customer-side access. The MSP must clearly distinguish its responsibilities from Microsoft's, the backup provider's, and the client's.
Copyable Service Definition
| Service field | Client-specific entry | Evidence |
|---|---|---|
| Protected scope | [Tenants, workloads, object types, included/excluded identities and sites] | Approved scope register and platform reconciliation. |
| Backup operation | [Configured schedule, retention, latest usable point definition] | Configuration and job history. |
| Recovery service | [Supported objects, source dates, destinations, conflict handling] | Current capability matrix and representative restore results. |
| Client objective | [RPO/RTO target by scenario] | Business approval and measured test. |
| Monitoring | [Review owner, cadence, stale-point threshold, escalation] | Ticket trail and latest review. |
| Request handling | [Authorized requesters, approvers, identity verification, priority] | Request and approval record. |
| Commercial terms | [Seats, tenants, storage/retention, minimums, pass-through costs] | Monthly reconciliation and client agreement. |
| Offboarding | [Stop date, retained-data decision, access, deletion, final billing] | Approved exit record. |
Tenant Onboarding Procedure
- Qualify the requirement: Use the policy template to identify required workloads, objects, retention, recovery destinations, and business owners.
- Create the tenant record: Record legal client name, Microsoft tenant ID, technical contact, security contact, billing owner, data-residency decision, and escalation contacts.
- Authorize access: Record the application identity, requested Microsoft Graph permissions, consenting administrator, credential owner, grant date, and revocation path.
- Run preflight: Reconcile each required handler as passed, failed, or unsupported. Resolve failures or obtain written risk acceptance before production.
- Configure scope and policy: Record selected identities, sites, workloads, schedule, retention, exclusions, and deleted-user handling. Do not assume a departed identity remains billable or protected; document the selected product and contract behavior.
- Establish the first usable point: Review item-level errors and completion state. A created job does not establish protection.
- Test recovery: Restore a representative supported object to an approved destination and record fidelity and elapsed time.
- Obtain acceptance: The client owner approves scope, known gaps, measured results, operating contacts, and commercial inputs.
Tenant Isolation Test
North Brook Vault publicly describes tenant-scoped credentials, jobs, snapshots, schedules, and policies. Treat that as a capability to validate, not permission to skip access testing.
- [ ] Identity boundary: Confirm each credential is associated with the intended tenant and cannot enumerate another client's source data.
- [ ] Console boundary: Test each MSP operator role against allowed and denied client contexts.
- [ ] Job boundary: Verify source tenant, snapshot, policy, and restore destination before approval.
- [ ] Request boundary: Require client identity and authority verification before revealing or restoring data.
- [ ] Error boundary: Confirm logs, tickets, exports, and screenshots used for support do not expose another client's identifiers or content.
- [ ] Removal boundary: Disable an operator and verify access removal without affecting other assigned operators.
Operating RACI
| Activity | Client | MSP | Backup provider |
|---|---|---|---|
| Approve requirements and risk | Accountable | Consulted/facilitates | Supplies capability evidence |
| Grant tenant consent | Accountable/responsible | Coordinates if authorized | Publishes required permissions |
| Operate service infrastructure | Informed | Informed/escalates | Accountable/responsible |
| Review tenant outcomes | Accountable for accepted risk | Responsible under service definition | Provides job state and support |
| Approve a restore | Accountable | Verifies request and operates | Operates supported service workflow |
| Accept restored data | Accountable/responsible | Records result | Addresses service defects |
Monitoring and Escalation Checklist
Microsoft Graph throttling is expected platform behavior, not proof of a provider outage. Microsoft's current guidance requires clients to handle HTTP 429 responses and honor retry instructions. No MSP tier should promise zero throttling.
- [ ] Review latest usable point for every contracted scope, not just the most recent job start.
- [ ] Review partial failures by handler, object, permission, throttling, deleted source, and unsupported type.
- [ ] Open a ticket with tenant, affected scope, business objective, error, owner, due time, and escalation state.
- [ ] Notify the client when the latest usable point exceeds the agreed notification condition. Do not invent an SLA not in the service agreement.
- [ ] Close with evidence showing a new usable point or an approved exception.
Billing Reconciliation
Reconcile billing from platform and contract evidence, not an assumed license count. North Brook Vault's public formula includes protected seats, additional tenants, monthly new backup data, retention, included allowances, and a monthly minimum. Use the pricing calculator for the approved formula, then record any MSP service margin or client-facing packaging separately.
| Billing period | [Start/end date and invoice reference] |
|---|---|
| Protected seats | [Count, evidence source, changes, departed-user decision] |
| Tenants | [Active tenant count and onboarding/offboarding dates] |
| Storage/retention inputs | [Monthly new data, retention, estimate versus actual source] |
| MSP service components | [Monitoring, support, restore labor, included/excluded work] |
| Approved variance | [Difference, cause, client notification, owner] |
Client Review Evidence
A QBR should show service decisions, not claim compliance. Include protected scope, latest usable points, failed or stale scopes, restore requests, test results, open exceptions, seat/storage changes, and planned client changes. North Brook Vault provides job state and history but does not provide a compliance report. The MSP must build any client review from validated operational records and must not label it a certification.
North Brook Vault Coverage and Limits
North Brook Vault's managed Microsoft 365 backup for MSPs uses provider-managed infrastructure and storage, tenant-scoped operations, service-side monitoring, retention policies, and selective restore handlers for supported Exchange, OneDrive, SharePoint, and Teams objects. The MSP remains responsible for reviewing tenant outcomes, client access, request authorization, escalation, service packaging, billing reconciliation, and recovery acceptance.
North Brook Vault does not offer customer-selected S3 or on-premises deployment, native Object Lock enforcement, OneDrive version-history capture, PST/PDF/ZIP export, compliance reports, or a zero-throttling guarantee. Teams chats, channel messages, and channel structures are not restorable. Set service targets only after using the RTO/RPO worksheet in a representative restore test, and operate production with the backup operations checklist.
Service Launch Decision
Launch a client only after onboarding acceptance, isolation checks, a usable recovery point, a representative restore, named monitors, billing inputs, and offboarding ownership are complete. Sell the tested service boundary, not an unlimited "Microsoft 365 backup" promise.
Review the MSP backup service Discuss an MSP recovery consultation