Managed Microsoft 365 Backup With Verifiable Recovery

North Brook Vault operates backup infrastructure and provider-managed storage for supported Exchange, OneDrive, SharePoint, and Teams data. Buyers define the required objects, then validate each available restore path rather than relying on a workload-wide promise.

Buy the operating model and the recovery scope together.

The service separates provider operation from customer accountability. Buyers using the Office 365 name can evaluate the same offering as a managed Office 365 backup solution. It is an additional recovery control, not a replacement for Microsoft-native recovery, Purview, legal hold, or business approval.

Good fit

Managed service, owned decisions

  • You prefer provider-operated service infrastructure and payload storage.
  • You can scope protection by tenant, workload, identity, site, drive, and object type.
  • Your operators will review job history and item-level failures.
  • Your business owners can approve and accept representative recovery results.
No-fit signals

Requirements the service does not meet

  • Customer-selected S3, local, NAS, or on-premises storage is mandatory.
  • Native Object Lock configuration or enforcement is mandatory.
  • OneDrive historical file-version capture is a required backup outcome.
  • Teams message or channel reconstruction, legal export, or a compliance report is required.

Separate what is captured from what can be restored.

This is the current decision boundary. A registered capture handler does not imply a restore handler, full structural reconstruction, or universal metadata fidelity.

Current North Brook Vault capture and restore statements. Validate required fields, destination, identity mapping, conflict behavior, and fidelity before rollout.
Workload / object Current capture Current restore Decision limit
Exchange data Supported captureSelected messages, folders, calendars, and contacts through registered Microsoft Graph handlers. Selective restoreRestore varies by object type. Confirm the exact handler, destination, and required properties. No claim of restoring every captured object or complete mailbox configuration. No PST export.
OneDrive drive items Supported captureCurrent files, folders, content, metadata, hierarchy, and separate permission snapshots. Supported restoreSelective drive-item restore. Test parent reconstruction, identity mapping, permissions, and conflicts. File version history is not captured. Permission snapshots do not prove universal permission restoration.
SharePoint list items Supported captureLists, list items, and list-item versions have registered capture handlers. Supported restoreSelective restore supports list items. Test required fields, attachments, lookups, people fields, IDs, item versions, and conflicts.
SharePoint drive items Supported captureCurrent document-library files, folders, content, and metadata. Supported restoreSelective restore supports site drive items. No separate historical document file-version handler. Test paths, metadata, permissions, destination, and conflicts.
SharePoint site pages Supported captureSite pages have a registered capture handler. Supported restoreSelective restore supports site pages. Validate web parts, references, layout, assets, publication state, and target behavior.
SharePoint structures Capture variesSites, lists, content types, columns, and term groups have registered or object-dependent capture paths. No current restore claimNo complete site creation, full-site rollback, list-structure, content-type, column, or term-group restore claim. Use native controls, documented manual reconstruction, Microsoft 365 Backup, or another product when structure recovery is mandatory.
Teams membership Supported captureTeams, team members, channels, and channel members have registered capture handlers. Limited restoreCurrent Teams restore support covers team-member objects. Test identity, membership role, target team, duplicate behavior, and authorization. No complete team or channel reconstruction claim.
Teams messages and configuration Capture onlySupported channel messages, chats, chat messages, tabs, apps, and permitted meeting metadata have registered capture paths. Not restorableNo chat-message, channel-message, channel-structure, tab, app, or meeting-transcript restore claim. No PST, PDF, ZIP, or transcript export. Use Purview or another approved control for legal search and export.
Teams files Underlying workloadChannel files follow SharePoint capture; chat-shared files generally follow OneDrive capture. Underlying workloadOnly the corresponding supported SharePoint or OneDrive drive-item restore path applies. Test Teams links, permissions, ownership, and destination separately. A message snapshot is not a file backup.

Know who operates, decides, and accepts.

North Brook Vault runs the contracted backup service. The customer and MSP remain responsible for business scope, authorized access, request handling, and recovery acceptance.

Activity North Brook Vault Customer or MSP Acceptance evidence
Service infrastructure and storage Operates service components, provider-managed payload storage, retention processing, and service-side monitoring. Reviews architecture, residency needs, contractual controls, and fit. Approved service boundary and written terms.
Tenant connection and consent Publishes required Graph permissions and provides preflight visibility. Approves tenant consent, application identity, authorized administrators, exclusions, and revocation path. Tenant record, consent record, and passed or accepted preflight results.
Protection policy Runs configured schedules, job execution, and retention processing. Approves protected objects, schedule, retention, exclusions, deleted-user handling, and objectives. Scope register, policy configuration, and first usable point.
Monitoring and exceptions Surfaces job state, history, progress, and structured item-level errors; addresses service-side defects. Reviews tenant outcomes, investigates partial failures, opens tickets, escalates, and communicates under its service definition. Ticket trail, new usable point, or approved exception.
Recovery request and result Provides supported service workflows and service support. Verifies requester authority, approves destination and conflict handling, runs the supported restore, and obtains business acceptance. Request approval, recovery point, operator record, result comparison, and owner acceptance.
Offboarding Applies the contracted service, access, retention, deletion, and support terms. Approves stop date, retained-data decision, recovery access, credential revocation, client communications, and final billing. Approved exit record governed by the written agreement.

Three stages, three acceptance gates.

Treat access, successful capture, and successful recovery as separate outcomes. None should be inferred from the previous stage.

  1. 01

    Connect

    Identify the tenant and authorized owners, grant the documented Graph permissions, reconcile preflight results, and record the revocation path.

  2. 02

    Protect

    Configure scope, schedule, and retention. Reconcile discovered objects, completed jobs, partial failures, item-level errors, and the latest usable point.

  3. 03

    Recover

    Authorize a supported object and destination, record conflict handling, compare the restored result with acceptance criteria, and retain the decision evidence.

Operational boundaries worth reviewing.

These controls must be evaluated as a managed-service design. They do not create automatic immutability, compliance, permission fidelity, or guaranteed recovery objectives.

Storage

Provider managed

North Brook Vault operates payload storage. Customers do not select or administer a backend S3 bucket, local path, NAS, or on-premises destination.

Retention

Policy scoped

Retention is configured with the protected scope and processed by the service. Confirm duration, exclusions, exit handling, and pricing inputs in writing.

Security review

Evidence, not labels

Review permissions, administrator roles, support access, residency requirements, deletion paths, and incident ownership. Native Object Lock is not provided.

Tenant separation

Scoped records

Credentials, jobs, snapshots, schedules, and policies are associated with the intended tenant. Buyers should still test operator and support boundaries.

Know the no-fit conditions.

Use another control or a layered design when a mandatory outcome falls outside these boundaries. Do not turn capture, managed storage, or scheduled jobs into a broader claim.

Review the storage decision guide

  • DeploymentNo customer-selected S3, local file, NAS, or on-premises deployment.
  • Storage controlNo native Object Lock configuration or enforcement.
  • OneDriveNo capture of OneDrive file version history.
  • TeamsNo restore of chat messages, channel messages, or channel structure.
  • ExportNo PST, PDF, ZIP, transcript, or legal-production export.
  • ComplianceNo compliance report, certification outcome, or legal-hold service.
  • Microsoft GraphNo guarantee of zero throttling; item outcomes and retries must be monitored.
  • Recovery objectivesNo invented or universal RPO, RTO, speed, fidelity, or recovery guarantee.

Published inputs, one authoritative calculator.

Use these rates for initial planning, then use the pricing page to calculate a scenario. A written proposal controls final price and contractual terms.

Managed service $5 / protected seat / month

The calculated monthly total is subject to a $199 account minimum.

Tenant fees First tenant included

Each additional tenant is $25/month. Every tenant includes 1 GB of storage.

Retention First month included

Chargeable retained storage starts in month two under the published estimate.

Managed storage $0.12 / GB-month

Applied to estimated billable retained storage after included retention and tenant storage allowances.

Estimate boundary Actual volume can differ

Delta growth, compression, retained object volume, taxes, and exceptional work affect final cost.

Final terms Written proposal controls

Negotiated terms and MSP-added monitoring, support, recovery labor, or margin are separate.

Monthly estimate = max($199, seats × $5 + max(0, tenants - 1) × $25 + max(0, monthly GB × max(0, retention months - 1 included month) - tenants × 1 GB) × $0.12)

Use the pricing calculator

Bring requirements that can be accepted or rejected.

The consultation maps business scenarios to current service capability and evidence. It does not claim a formal pilot program, guaranteed result, or predetermined rollout approval.

Decision criterion Evidence to bring or create Acceptance question
Protected scope Tenants, identities, mailboxes, sites, drives, Teams, object types, exclusions, and business owners. Does every required object have a current capture path?
Access Application identity, Graph permissions, consenting administrator, restrictions, preflight outcome, and revocation path. Is access authorized, scoped, and operational for each required handler?
Usable point Configured policy, job history, recovery-point identifier, object counts, item failures, throttling, and open exceptions. Is there a recovery point with understood gaps rather than only a completed job?
Restore path Required source date, object, destination, identity mapping, conflict option, and documented handler support. Can the required object be restored to an approved destination?
Result fidelity Content comparison plus required hierarchy, fields, timestamps, permissions, identities, links, and recorded differences. Does the result satisfy the business owner's stated acceptance criteria?
Operating readiness Named monitor, escalation path, authorized requesters, recovery approver, acceptance owner, pricing inputs, and offboarding owner. Can the buyer operate the service after rollout without relying on undocumented assumptions?

Use the detailed procedure for each decision.

These canonical guides contain deeper matrices, native Microsoft context, evidence checklists, and no-fit boundaries.

EXO / Recovery

Exchange Online

Classify item, folder, mailbox, retention, and destination requirements before choosing a restore path.

Read Exchange guide
ODB / Recovery

OneDrive for Business

Separate current drive-item snapshots from Microsoft's native version history and deleted-user lifecycle.

Read OneDrive guide
SPO / Recovery

SharePoint Online

Map list items, drive items, pages, versions, structures, permissions, and complete-site requirements separately.

Read SharePoint guide
MST / Recovery

Microsoft Teams

Separate membership, files, messages, channels, meetings, preservation, restore, and export outcomes.

Read Teams guide
OPS / MSP

MSP service delivery

Define onboarding, isolation, monitoring, escalation, billing, recovery acceptance, and offboarding.

Read MSP guide
OPS / Checklist

Backup operations

Use an operational checklist to review usable recovery points, failures, restores, and retained evidence.

Read operations guide
OPS / Test plan

Restore testing

Define approval, destination, fidelity, reconciliation, and acceptance evidence for a representative restore.

Read restore test plan
OPS / Objectives

RTO and RPO planning

Set scenario-specific objectives and measure them without relying on universal recovery promises.

Use the RTO/RPO worksheet
BUY / Comparison

Backup solution models

Compare native, managed SaaS, self-managed, and MSP delivery models against the same evidence gates.

Compare backup options

Questions that define service fit.

Use these answers as a starting boundary. Current object support and contractual terms still need to match your exact environment.

Capture and restore stated separately
What does North Brook Vault manage?

North Brook Vault operates the service infrastructure, provider-managed payload storage, scheduled job execution, retention processing, and service-side monitoring. The customer or MSP owns tenant consent, requirements, access approvals, recovery authorization, and result acceptance.

Which Microsoft 365 data can be restored?

Restore support is object-specific, not workload-wide. Current supported paths include OneDrive drive items; SharePoint list items, site drive items, and site pages; and Teams team-member objects. Exchange restore is selective and must be confirmed for each required object. Capture-only objects do not satisfy a recovery requirement.

Can I choose the backup storage destination?

No. North Brook Vault is managed SaaS with provider-managed storage. It does not provide customer-selected S3, local file, NAS, or on-premises destinations, and it does not currently provide native Object Lock configuration or enforcement.

How is North Brook Vault priced?

Public pricing is $5 per protected seat per month with a $199 monthly account minimum. The first tenant and first retention month are included; each additional tenant is $25 per month, each tenant includes 1 GB of storage, and billable retained storage is $0.12 per GB-month. A written proposal controls final pricing.

What should be validated before rollout?

Map each required object to a current capture and restore path, confirm Graph permissions and tenant scope, review job and item-level outcomes, restore representative supported data to an approved destination, compare content and required metadata, and obtain business-owner acceptance. These are consultation criteria, not a promise of a formal pilot program.

Requirements before rollout

Validate the recovery path you need.

Email the required tenants, objects, retention, destination, fidelity checks, operator roles, and no-fit constraints. The consultation will map them to current service support and unresolved decisions.