Disaster Recovery

SharePoint Online Disaster Recovery: Admin Runbook and Exercise Guide

Updated Aug 21, 20267 min readBy Solutions Engineering

Direct answer: a SharePoint disaster recovery plan must say which tool recovers each incident, which objects it can restore, who approves the action, where restored data goes, and how success is measured. "We have backups" is not a plan, and a successful backup job is not recovery evidence.

Correct the native-tool assumptions before writing the runbook. SharePoint Files Restore rolls a document library back for activity in the previous 30 days; it is not a full-site rollback in the SharePoint admin center. Deleted SharePoint sites can normally be restored by an administrator during their documented 93-day retention window. Microsoft 365 Backup is a separate product with SharePoint site and selected-content restore workflows. Microsoft's resiliency documentation and Microsoft 365 Backup restore procedure should be attached to the runbook and reviewed when the service changes.

SharePoint Incident and Recovery Matrix

IncidentFirst candidateNorth Brook Vault boundaryDecision gate
One recently deleted file, folder, or list itemRecycle bin or version history where applicableSelective restore for supported site drive items or list items from retained snapshotsAge, object type, metadata, permissions, and destination
Mass document-library deletion or overwriteFiles Restore for activity in the prior 30 days; Microsoft 365 Backup if protectedRestore supported drive items individually or in tested batches; no full-library rollback claimBlast radius, clean recovery point, later legitimate changes, throughput
Deleted SharePoint siteRestore deleted site within Microsoft's documented window or use Microsoft 365 BackupNo current full-site creation or site-rollback handlerSite still recoverable, target URL, dependencies, and site fidelity
Custom-list damageRecycle bin, retention, or Microsoft 365 Backup where applicableSelective list-item restore is supported; list-structure restore is not currently claimedFields, attachments, versions, lookups, and list schema
Deleted or corrupted site pageNative version/recycle behavior where availableSelective site-page restore is supportedWeb parts, assets, publication state, and rendering
Permission, content type, column, taxonomy, workflow, or app damageAudit and manual correction, Microsoft-native recovery where documented, or product with explicit structural restoreNorth Brook Vault does not claim universal structural or permission restorationExact configuration objects and tested reconstruction procedure
Widespread ransomware or malicious administrationContain identities and sync, preserve evidence, then select native, Microsoft 365 Backup, or independent recovery by objectSupported selective restores only; managed storage is not native Object LockClean point, affected tenants/sites, credential boundary, and recovery order

Use the SharePoint recovery decision guide to compare the candidate layers and the SharePoint object coverage guide to determine what North Brook Vault can and cannot restore.

Incident Procedure

  1. Declare and assign: record incident commander, SharePoint administrator, security lead, business owner, recovery operator, approver, and communications owner.
  2. Contain without destroying evidence: disable compromised sessions or accounts, pause affected sync clients and automation, preserve audit logs, and avoid indiscriminate deletion.
  3. Identify blast radius: list affected sites, libraries, lists, pages, users, time range, actions, object IDs, and known-good timestamps.
  4. Protect later legitimate work: export or snapshot changes made after the proposed recovery point before using a rollback operation.
  5. Choose the least disruptive path: single-item native restore, Files Restore, deleted-site restore, Microsoft 365 Backup, North Brook Vault selective restore, or manual reconstruction.
  6. Confirm authorization: require business approval for rollback, overwrite, original-location restore, or any action that can remove later changes.
  7. Restore to an alternate destination first where possible: validate content and metadata before replacing production objects.
  8. Verify and reconcile: compare counts, hashes, fields, versions, pages, permissions, links, and user access.
  9. Return to service: re-enable automation and sync in stages, monitor for repeated changes, communicate residual gaps, and retain the evidence packet.

Runbook Inputs

Seeded Recovery Exercises

  1. Single-object exercise: delete a file and a custom list item, recover each through the least disruptive path, and compare metadata.
  2. Library-corruption exercise: edit and delete a seeded set of files, preserve two later legitimate edits, and test Files Restore or the approved alternative in a nonproduction library.
  3. Selective-backup exercise: recover supported site drive items, list items, and a site page from a retained North Brook Vault snapshot.
  4. Deleted-site exercise: delete an approved pilot site and use Microsoft's documented deleted-site or Microsoft 365 Backup path. Do not represent this as a North Brook Vault site restore.
  5. Structural-loss tabletop: simulate damaged permissions, columns, content types, taxonomy, and workflows; prove the manual or alternate-product reconstruction path.
  6. Credential-compromise tabletop: assume a tenant admin and backup operator are compromised; review containment, storage boundary, escalation, and deletion controls.

Run exercises after material product, permission, retention, or site-architecture changes, not only on an arbitrary annual date. Never delete a production site merely to prove a product claim.

Pass/Fail Evidence Checklist

North Brook Vault Fit and No-Fit Boundaries

North Brook Vault fits a SharePoint DR design when supported list items, site drive items, or site pages need selective restoration from retained managed-service snapshots and those workflows pass the tenant pilot. Customers remain responsible for tenant authorization, incident command, business approval, customer-side access, and representative exercises.

It is not currently a complete-site DR product. It does not claim full-site rollback or creation, historical document-library version capture, universal configuration or permission restoration, native Object Lock, or uninterrupted access during a provider incident. A complete runbook may need SharePoint native recovery, Microsoft 365 Backup, Purview, manual reconstruction, and North Brook Vault together.

Review SharePoint recovery coverage Discuss a SharePoint DR consultation Review managed-service pricing