Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Most Office 365 Admins Rely on Recycle Bin for Data Backup
Oldest First  |  Newest First  |  Threaded View
wayno
33%
67%
wayno,
User Rank: Apprentice
7/19/2017 | 4:34:41 PM
Recycle bins, really?
I wouldn't have believed it: using the "round file" as a backup tool.  It sounds like a bad movie script and an even worse real-world practice.  Thanks!
REISEN1955
0%
100%
REISEN1955,
User Rank: Ninja
7/20/2017 | 8:05:45 AM
Re: Recycle bins, really?
Insane practice.  I proudly saved one of my 501C3 accounts from a horrible Cryptolocker attack in January of 2014 - ransomware from executive director's machine to server at 1:45 am.  Everything encrypted.  Because I had a reliable off-site backup system (dedicated computer on my network) for each account, I was able to restore ALL of their data within 3 hours the next day.  Using recycle bin????  Babies.  And fools.
dmstork
100%
0%
dmstork,
User Rank: Strategist
7/20/2017 | 8:49:45 AM
Some nuances
While the key takeaway is valid (admins should have a valid plan to restore data with private cloud SaaS/IaaS solutions), there are some nuances to be made:

-SharePoint Online Recycle bin retention is 93 days not 30

-SharePoint Online elements can be restored from a backup controlled by Microsoft, you'd have to contact Microsoft Support. (I do not have any experiences with this however)

-Stricly speaking Exchange Online does not use the Recycle Bin, but has it's own solution (Deleted Item Retention) which has a retention of 14 days per default but can be configured up to 30 days: 
But, that is only true for pure Exchange items; it gets trickier with Office 365 Groups or Microsoft Teams, which also leverage SharePoint Online elements.

-Not enabled per default, but still available for all/most plans and for Exchange and SharePoint: In-Place Hold or Litigation Hold/Preservation policies. Which can help the organizations with the challenges described in the article.

While there are solutions out there that can backup elements from SharePoint/Exchange Online, there are still challenges with restoring (especially with features that use multiple services like Office 365 Groups).

Being an Exchange on-prem/Online specialist (and a Microsoft MVP, Office Servers & Services), I often get asked about backing up Exchange Online. There are 4 copies of the data, spread over two datacenters in different regions and one of those four has a delay (lagged), providing a point in time restore option. Combined with the forementioned Hold features Exchange Online has a more robust infrastructure than most of my on-premises Exchange customers have. And probably more cost effective in almost all cases.

So, most of the critism isn't really valid for Exchange Online admins/users. However, awareness from those responsible should indeed be better as I've had to explain this numerous times.

Another note: I haven't read the original survey from Barracuda so I can't really comment on the content. However, I would like to mention that Barracuda has got an Office 365 backup solution, so it's in their own interest to at least highlight possible challenges with native Office 365 solutions. I'm not saying they are spreading falsehoods, but IMHO it's relevant.
bluvg
100%
0%
bluvg,
User Rank: Apprentice
7/20/2017 | 6:53:30 PM
Self-serving?
While O365 backup is an important discussion to have, this seems perhaps self-serving when Barracuda just released their SharePoint backup solution only a few months ago (Oct 2016). Did it only become important because they started to have an offering for it? Barracuda backs up Exchange online, SharePoint online, and OneDrive for Business. If you take the premise further, what should you do with Teams, Groups, Project Online, Planner, Sway, etc.? Ask Barracuda's competitors? Or perhaps approach backup in O365 differently?

Throwing current strains of ransomware out there seems a bit of a red herring with regard to Exchange Online and SharePoint Online. OneDrive for Business is a potential target, but if your ODfB account does get hit with ransomware, how likely is it that you'll pass the Recycle Bin restore window? And how fast is it to restore from the Recycle Bin vs. restore from an external backup appliance? And how long is your on-prem backup rotation?

It's a great marketing strategy to create the notion that "everyone knows you need an O365 backup solution," then implicitly scold non-compliant admins. The reality is as it always has been: you assess the technology and then assess your risk. You might determine that a traditional (on-prem model) backup solution--such as Barracuda's--would be desirable. Or, you might realize that cloud backup considerations are different, and traditional backup solutions may not be the right fit or perhaps even no longer apply. But we shouldn't let this type of marketing strategy take hold and distract us from proper due diligence.
Shantaram
50%
50%
Shantaram,
User Rank: Ninja
7/22/2017 | 5:32:47 AM
Re: 192.168.0.1
Useful and interesting article. Thanks. Just continue composing this kind of articles
SandraD242
50%
50%
SandraD242,
User Rank: Apprentice
8/21/2017 | 7:03:36 AM
Thanks for posting this article
Thanks for posting this article. Yes, it is true that most of the admins rely on Recycle bin for data backup. But my clients use SysTools Office 365 Backup to backup Office 365 mailboxes. I would like to share this solution with the users and I hope it helps.
Winema
50%
50%
Winema,
User Rank: Apprentice
8/28/2017 | 3:58:14 AM
Re: Recycle bins, really?
Thank you,was looking for this information


COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
'BootHole' Vulnerability Exposes Secure Boot Devices to Attack
Kelly Sheridan, Staff Editor, Dark Reading,  7/29/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17364
PUBLISHED: 2020-08-05
USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
CVE-2020-4481
PUBLISHED: 2020-08-05
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181848.
CVE-2020-5608
PUBLISHED: 2020-08-05
CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass authentication and send altered c...
CVE-2020-5609
PUBLISHED: 2020-08-05
Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to cre...
CVE-2020-8607
PUBLISHED: 2020-08-05
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentia...