Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Most Office 365 Admins Rely on Recycle Bin for Data Backup
Newest First  |  Oldest First  |  Threaded View
Winema
50%
50%
Winema,
User Rank: Apprentice
8/28/2017 | 3:58:14 AM
Re: Recycle bins, really?
Thank you,was looking for this information
SandraD242
50%
50%
SandraD242,
User Rank: Apprentice
8/21/2017 | 7:03:36 AM
Thanks for posting this article
Thanks for posting this article. Yes, it is true that most of the admins rely on Recycle bin for data backup. But my clients use SysTools Office 365 Backup to backup Office 365 mailboxes. I would like to share this solution with the users and I hope it helps.
Shantaram
50%
50%
Shantaram,
User Rank: Ninja
7/22/2017 | 5:32:47 AM
Re: 192.168.0.1
Useful and interesting article. Thanks. Just continue composing this kind of articles
bluvg
100%
0%
bluvg,
User Rank: Apprentice
7/20/2017 | 6:53:30 PM
Self-serving?
While O365 backup is an important discussion to have, this seems perhaps self-serving when Barracuda just released their SharePoint backup solution only a few months ago (Oct 2016). Did it only become important because they started to have an offering for it? Barracuda backs up Exchange online, SharePoint online, and OneDrive for Business. If you take the premise further, what should you do with Teams, Groups, Project Online, Planner, Sway, etc.? Ask Barracuda's competitors? Or perhaps approach backup in O365 differently?

Throwing current strains of ransomware out there seems a bit of a red herring with regard to Exchange Online and SharePoint Online. OneDrive for Business is a potential target, but if your ODfB account does get hit with ransomware, how likely is it that you'll pass the Recycle Bin restore window? And how fast is it to restore from the Recycle Bin vs. restore from an external backup appliance? And how long is your on-prem backup rotation?

It's a great marketing strategy to create the notion that "everyone knows you need an O365 backup solution," then implicitly scold non-compliant admins. The reality is as it always has been: you assess the technology and then assess your risk. You might determine that a traditional (on-prem model) backup solution--such as Barracuda's--would be desirable. Or, you might realize that cloud backup considerations are different, and traditional backup solutions may not be the right fit or perhaps even no longer apply. But we shouldn't let this type of marketing strategy take hold and distract us from proper due diligence.
dmstork
100%
0%
dmstork,
User Rank: Strategist
7/20/2017 | 8:49:45 AM
Some nuances
While the key takeaway is valid (admins should have a valid plan to restore data with private cloud SaaS/IaaS solutions), there are some nuances to be made:

-SharePoint Online Recycle bin retention is 93 days not 30

-SharePoint Online elements can be restored from a backup controlled by Microsoft, you'd have to contact Microsoft Support. (I do not have any experiences with this however)

-Stricly speaking Exchange Online does not use the Recycle Bin, but has it's own solution (Deleted Item Retention) which has a retention of 14 days per default but can be configured up to 30 days: 
But, that is only true for pure Exchange items; it gets trickier with Office 365 Groups or Microsoft Teams, which also leverage SharePoint Online elements.

-Not enabled per default, but still available for all/most plans and for Exchange and SharePoint: In-Place Hold or Litigation Hold/Preservation policies. Which can help the organizations with the challenges described in the article.

While there are solutions out there that can backup elements from SharePoint/Exchange Online, there are still challenges with restoring (especially with features that use multiple services like Office 365 Groups).

Being an Exchange on-prem/Online specialist (and a Microsoft MVP, Office Servers & Services), I often get asked about backing up Exchange Online. There are 4 copies of the data, spread over two datacenters in different regions and one of those four has a delay (lagged), providing a point in time restore option. Combined with the forementioned Hold features Exchange Online has a more robust infrastructure than most of my on-premises Exchange customers have. And probably more cost effective in almost all cases.

So, most of the critism isn't really valid for Exchange Online admins/users. However, awareness from those responsible should indeed be better as I've had to explain this numerous times.

Another note: I haven't read the original survey from Barracuda so I can't really comment on the content. However, I would like to mention that Barracuda has got an Office 365 backup solution, so it's in their own interest to at least highlight possible challenges with native Office 365 solutions. I'm not saying they are spreading falsehoods, but IMHO it's relevant.
REISEN1955
0%
100%
REISEN1955,
User Rank: Ninja
7/20/2017 | 8:05:45 AM
Re: Recycle bins, really?
Insane practice.  I proudly saved one of my 501C3 accounts from a horrible Cryptolocker attack in January of 2014 - ransomware from executive director's machine to server at 1:45 am.  Everything encrypted.  Because I had a reliable off-site backup system (dedicated computer on my network) for each account, I was able to restore ALL of their data within 3 hours the next day.  Using recycle bin????  Babies.  And fools.
wayno
33%
67%
wayno,
User Rank: Apprentice
7/19/2017 | 4:34:41 PM
Recycle bins, really?
I wouldn't have believed it: using the "round file" as a backup tool.  It sounds like a bad movie script and an even worse real-world practice.  Thanks!


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Why Cybersecurity's Silence Matters to Black Lives
Tiffany Ricks, CEO, HacWare,  7/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...