Insights

Protect business data across Microsoft 365, laptops and servers

1 October 2026

Review hybrid IT data protection across Microsoft 365, laptops, servers and cloud apps. Check backup coverage, access, retention and tested recovery.

Datto published guidance on 10 December 2025 about protecting business information spread across on-premises systems, SaaS applications, cloud infrastructure and employee devices. For Australian businesses using Microsoft 365 alongside laptops, servers and specialist cloud apps, the practical issue is visibility: can you identify every important record and recover it when something goes wrong?

Hybrid IT data protection starts with that question, not with buying another tool. Datto’s guidance highlights the need to manage protection across these environments. The checklist below turns that broad concern into checks for business owners, operations teams and IT leaders.

Start hybrid IT data protection with a data map

List the information needed to run each business process, then trace where it is created, stored, copied and shared. Ask finance, operations and sales to contribute: an IT asset register will not necessarily reveal a spreadsheet saved locally or a customer export in someone’s personal cloud account.

Use a simple register with these columns:

| Data location | What to identify | What to verify | |---|---|---| | Microsoft 365 | Exchange mailboxes, SharePoint sites, OneDrive accounts and Teams content | Which underlying workloads and data types are protected | | Laptops and desktops | Local folders, downloads and application files | Whether important files reach approved storage or endpoint backup | | On-premises servers | Shared drives, databases and business applications | Whether backups support usable application recovery | | Cloud infrastructure | Virtual machines, databases, storage and configuration | Whether recovery includes dependencies and access settings | | SaaS applications | Accounting, payroll, CRM and industry platforms | What the vendor can restore and what you must arrange |

Assign a business owner and technical contact to each entry. Record sensitivity, authorised users, backup method and the date recovery was last tested. An unknown field is a gap to investigate, not evidence that protection exists.

Separate backup, synchronisation, retention and availability

These controls solve different problems. Synchronisation makes files available across locations, but can also propagate deletion or unwanted changes. Retention preserves information under configured rules, but may not provide the recovery speed or scope your business needs. Service availability does not establish that a particular deleted record can be restored.

Microsoft 365 includes native recovery and retention capabilities, but their scope depends on the workload, configuration and licensing. Assess those capabilities against your requirements rather than assuming either that everything is protected or that native controls offer no protection.

For each system, ask:

  • Can we restore an individual item, an entire account and a larger dataset?
  • How far back can we recover, and what happens after that window?
  • Are permissions, versions, attachments and application relationships included?
  • What happens when a user leaves, a licence is removed or a subscription ends?
  • Can a compromised administrator delete both production data and its recovery copies?

A sound hybrid IT data protection plan documents these answers and identifies where additional backup is justified.

Check actual backup coverage, not just successful jobs

A green status report tells you a configured job completed. It does not prove every new site, device or application is included.

Compare the data register with backup configuration. Check whether newly created mailboxes, SharePoint sites, servers and cloud resources enter protection automatically or require manual enrolment. Review exclusions and investigate devices that have not connected recently.

For Teams, check coverage of the underlying services and supported content types. A product that protects files stored in SharePoint does not necessarily protect every Teams conversation or setting.

For servers and cloud databases, verify whether backups are application-consistent and whether recovery requires particular software versions, encryption keys or service accounts. For laptops, inspect where staff actually save work. Redirecting standard folders does not capture every local application database or downloaded file.

For SaaS platforms, obtain written details of restore options. A CSV export may preserve records without preserving attachments, relationships or the ability to rebuild a working application.

Restrict access to live data and recovery systems

Backups reduce the consequences of data loss; they do not stop information being stolen. Hybrid IT data protection also needs controls over who can read, change, export and delete data.

Prioritise these checks:

  • Require multifactor authentication, especially for administrators and remote access.
  • Separate everyday accounts from privileged administration accounts.
  • Review guest users, external sharing links and dormant accounts.
  • Remove former staff access and rotate shared credentials where necessary.
  • Limit application permissions and service accounts to their required functions.
  • Protect devices with encryption, patching and endpoint security.

Treat backup administration as a separate security boundary. Restrict who can change retention, remove recovery points or disable alerts. Where supported, use immutable or deletion-protected copies and test how those controls behave. Do not assume a label makes every backup unreachable to an attacker.

Our Microsoft 365 impossible travel checklist explains how to investigate suspicious sign-ins. Also review remote management access controls, because remote support tools can provide powerful access to both production and backup systems.

Set retention around business and legal needs

Keeping everything indefinitely increases storage, discovery and privacy burdens. Keeping too little can leave the business unable to answer a dispute or recover an older record.

Set retention by information category rather than applying one blanket period. Finance records, employee information, customer correspondence and temporary exports may need different treatment. Confirm applicable obligations with your legal or compliance adviser, including any legal hold requirements.

Document how retention applies to live systems, archives and backups. Explain what happens when a record is deleted from production but remains in a protected recovery copy, and how expired copies are removed.

Check where primary data and backups are stored, who can access them and whether subcontractors or cross-border support arrangements are involved. Hosting location alone does not establish compliance; contractual terms and access practices matter too.

Test recovery against business priorities

Recovery testing is where hybrid IT data protection becomes measurable. Start with two targets agreed by the business owner:

  • Recovery point objective: how much recent work the business can afford to lose.
  • Recovery time objective: how long the process can remain unavailable.

These are planning targets, not promises. Test whether the actual setup can meet them.

Choose realistic scenarios: a deleted customer folder, an unavailable laptop, a corrupted finance database and a compromised Microsoft 365 account. Restore into a safe location and have the relevant team confirm the result is complete and usable.

For applications, test more than whether a server starts. Confirm users can sign in, access records and complete a normal transaction. Include dependencies such as identity services, DNS, certificates, network access and integrations.

Record elapsed time, missing items, failed steps and the person responsible for remediation. If ransomware is suspected, preserve evidence and establish a clean recovery environment before reconnecting restored systems. Recovery should not reintroduce the original compromise.

Give the plan an owner and a review cycle

Assign someone to monitor failures and escalate unresolved gaps. Review coverage when systems, staff or suppliers change, and schedule recovery exercises based on business criticality.

Keep an accessible recovery runbook with contacts, restoration priorities, access procedures and escalation steps. Store it somewhere available if the main environment is down, without exposing sensitive credentials.

A useful management report shows unprotected systems, unresolved failures, the latest tested recovery results and overdue corrective actions. It should make clear what needs a decision, not simply display job counts.

Review your cyber security and recovery readiness

Tech Engine can help review your cyber security, managed IT and Microsoft 365 environment, identify protection gaps and plan practical recovery tests. To discuss your hybrid IT data protection priorities, call 1300 088 324 or email sales@techengine.au.

Want this applied to your business?

Request an AI Blueprint and we will map the processes worth automating first.

Request an AI Blueprint