Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Independent IT security review

Know the difference between retention and recovery.

Microsoft 365 keeps data available so the business can keep running, not as a substitute for backup. The review clarifies what native retention actually covers and where a deliberate recovery decision is still needed.

Separate native retention from true backup.

Recycle bins, versioning, and retention policies protect against some loss scenarios and not others. The review states plainly which scenarios each native control actually addresses.

Retention scope

Map mailbox, SharePoint, OneDrive, and Teams retention settings against their actual recovery windows, not an assumed default.

Deletion scenarios

Distinguish accidental deletion, malicious deletion, retention-policy expiry, and account offboarding, since native tools respond differently to each.

Litigation hold interaction

Confirm how retention and hold settings interact so recovery expectations match what is actually preserved.

Decide whether third-party backup is warranted.

A third-party backup product is a decision, not a default. The review connects that decision to actual risk and recovery requirements instead of a blanket recommendation.

Recovery point objective

Compare how much data loss is acceptable against what native retention windows and any backup product actually provide.

Recovery time objective

Assess how quickly a mailbox, site, or Teams workspace needs to be usable again after a loss event.

Cost and ownership

Document who would operate a third-party backup product, and what compensating process exists if one is not adopted.

Test recovery instead of assuming it works.

A backup or retention setting that has never been exercised is an untested assumption. The review looks for evidence of an actual recovery attempt.

Restore evidence

Confirm whether a real restoration-of a mailbox item, a document, or a Teams channel-has been performed and verified.

Scope of a test

Distinguish a full-item restore test from simply confirming a backup job completed without errors.

Documented outcome

Record what worked, what took longer than expected, and what the test revealed about the real recovery time.

Connect backup posture to remediation, not a purchase decision alone.

The review’s output is a decision record, not a product recommendation delivered in isolation from ownership and process.

Ownership

Assign who monitors backup job health and who is authorized to initiate a recovery.

Retention alignment

Reconcile backup retention length with regulatory, contractual, or internal data-retention expectations.

Review cadence

Set a sensible interval to revisit recovery objectives as the organization’s data and risk tolerance change.

Next step

Define the review before sharing evidence.

Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.