Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Reality Check: Microsoft's Backup Promise Falls Short


While Microsoft 365 and Azure offer powerful tools for business productivity, organizations relying on these services must be aware of the limitations of their provider's native backup and recovery capabilities. By implementing dedicated cloud-to-cloud backup solutions and prioritizing cyber resilience, businesses can protect themselves against catastrophic data loss and ransomware attacks.

  • Organizations relying on Microsoft 365 and Azure must be aware of the limitations of their provider's native backup and recovery capabilities.
  • The assumption that these providers' retention and recovery capabilities are enough to protect data is fundamentally flawed.
  • The divide between availability and true cyber resilience has widened due to evolving cyberattacks, such as AI-powered phishing attacks and credential compromise.
  • Organizations often retain functions on-premises while moving others to cloud models, leaving a weak link when ransomware strikes.
  • Dedicated cloud-to-cloud backup solutions stored outside the main SaaS tenant can help ensure critical assets remain safe from attack.
  • Traditional approaches to backing up data are no longer sufficient on their own and require a more comprehensive approach to withstand disaster.



  • In an era where cybersecurity threats are increasingly sophisticated and targeted, organizations relying on cloud-based services like Microsoft 365 and Azure must be aware of the limitations of their provider's native backup and recovery capabilities. Recent studies and expert opinions suggest that these providers often prioritize availability over true cyber resilience, leaving businesses vulnerable to catastrophic data loss and ransomware attacks.

    According to Guy Matthews, a writer for The Next Platform, organizations often fall prey to the misconception that Microsoft's comprehensive native retention and recovery capabilities are enough to protect their data. However, this assumption is fundamentally flawed, as these providers operate on the same shared responsibility model as other major SaaS providers. In the event of a cyberattack, the cloud provider handles some responsibilities, while the subscriber assumes others.

    Experts note that this divide between availability and true cyber resilience has widened in recent years due to evolving cyberattacks, such as AI-powered phishing attacks and credential compromise. These sophisticated threats exploit human weakness, removing the need for traditional vulnerabilities, making it easier for attackers to gain access to sensitive data.

    Moreover, organizations often retain some functions on-premises while moving others to infrastructure and platform-as-a-service (IaaS and PaaS) models, but fail to protect and manage everything to the same level of quality. This "as a service" model may be appealing, but it leaves a weak link when ransomware strikes.

    To address this issue, some organizations are turning to dedicated cloud-to-cloud backup solutions stored outside the main SaaS tenant, which can help ensure that critical assets remain safe from attack even if the primary environment is compromised. Experts emphasize the importance of such protection and recommend keeping copies of regularly targeted data in an immutable storage solution that can be recovered from, even if the Microsoft or Google ecosystem goes down.

    In this context, Datto's cybersecurity and data protection business, owned by Kaseya, has developed a platform designed to close the gap between availability and recovery. Their solutions store protected copies of tenant data in the Datto Cloud, outside the Microsoft environment, ensuring that a compromised production tenant does not take the recovery point down with it.

    Experts stress that organizations need to recognize that ransomware attacks are becoming more frequent, and that traditional approaches to backing up data are no longer sufficient on their own. Anticipating disaster is not enough; the organization must be set up to withstand it. That means being as certain as possible that the Microsoft environment can be recovered rapidly, down to the last scrap of data.

    In summary, while Microsoft 365 and Azure offer powerful tools for business productivity, organizations relying on these services must be aware of the limitations of their provider's native backup and recovery capabilities. By implementing dedicated cloud-to-cloud backup solutions and prioritizing cyber resilience, businesses can protect themselves against catastrophic data loss and ransomware attacks.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Reality-Check-Microsofts-Backup-Promise-Falls-Short-ehn.shtml

  • https://www.theregister.com/security/2026/08/13/sponsored-the-backup-microsoft-never-promised-you/5284957


  • Published: Thu Aug 13 11:55:29 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us