The backup Microsoft never promised you

← Back to the feed

The backup Microsoft never promised you

The Register · 3 hours ago

The sponsored article argues that organisations should not assume Microsoft’s native Microsoft 365 and Azure tools will provide full recovery after a ransomware incident. It says Microsoft follows a shared-responsibility model: it keeps services available, while customers remain responsible for restoring their own data, identities and accounts to a known safe point. This matters because an organisation’s ability to resume operations may depend on backup arrangements that go beyond Microsoft’s standard retention and governance features.

The article says attackers increasingly exploit stolen credentials and identities rather than technical vulnerabilities, using phishing, social engineering, spoofed sites and AI-assisted credential testing. It identifies Microsoft Entra ID as a significant potential attack route, arguing that compromised credentials can allow access to mailboxes, OneDrive, SharePoint and Teams without necessarily triggering alarms. It also notes that managed service providers face additional pressures from client service-level agreements, preferred tools, staffing and profitability.

  • Microsoft availability does not guarantee ransomware recovery.
  • Customers retain responsibility for restoring their own data.
  • Stolen identities are presented as a growing attack route.

Cybersecurity Technology

Read the full article at the source →