Skip to main content
CybersecurityCloud Security

Microsoft's Shared Responsibility Model Exposes SaaS Backup Gaps

Empty office workspace with laptop, papers, and city view, conveying shared responsibility.

"There's a common misconception about what Microsoft is responsible for, as distinct from the service they're providing," explains Brent Torre, GM of cyber resilience.

Microsoft's operating model and the limits of native recovery

The core claim of the source is blunt: Microsoft keeps services running, but it does not promise to restore customer data to a specific known-good point. The company “operates on the same shared responsibility model as other major SaaS providers,” the reporting states, and its native retention and recovery tools are built to address short-term accidental deletion and governance—not to serve as a cyber resilience backup against ransomware. As Torre puts it, “They are not a backup solution and will not protect against ransomware or recover data.”

Identity attacks, AI, and Entra ID as the primary vector

The threat picture described in the source stresses that modern attackers focus on identity rather than exploiting code vulnerabilities. The report says identity has become “the primary attack surface,” and that Microsoft Entra ID—the cloud identity and access management tool—is now “a prime vector for attack.” The piece underscores how credential compromise can let adversaries read mailboxes, OneDrive, SharePoint and Teams before launching a ransomware strike.

The source also highlights the role of AI in adversary toolkits: automated bots and AI-driven phishing and social-engineering techniques are used to exploit password reuse and leaked credentials at scale. Microsoft, the source reports, “tracks more than 4,000 identity attacks every second and analyzes 38 million identity risk detections daily,” a statistic used to underscore how persistent and automated these identity threats have become.

Why cloud availability is not the same as recoverability

The article distinguishes availability—keeping services online—from recoverability—restoring data to a safe pre-incident state. According to the source, organizations increasingly mix on-premises, SaaS and IaaS/PaaS workloads, and they do not always protect or back up each environment uniformly. That heterogeneity enlarges the gap between mere availability and the ability to recover clean, uncompromised data after an attack. Compliance regimes and cyber insurance requirements are also mentioned as forces pushing organizations to formalize off-platform backup and recovery approaches.

Datto, Kaseya, and the off-tenant backup model

The source identifies Datto—described as a cybersecurity and data protection business owned by Kaseya—as offering products intended to close this gap. Named offerings include Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID. The approach is simple in concept and specific in practice: pull copies of targeted tenant data out of the Microsoft tenant and store them in the Datto Cloud (or another third-party datacenter) so that a compromised production tenant cannot take recovery points with it.

Brent Torre frames the prescription in concrete terms: “At Kaseya we regularly recommend that you keep a copy of your data, independent of the primary environment it's operating in. This needs to be something immutable that you can recover from even if the Microsoft or Google or Salesforce ecosystem goes down.” He also claims, of Datto’s M365 backup, “we're protecting one million users worldwide.”

What this means for MSPs, IT leaders, and cyber insurers

MSPs must balance strict SLAs, clients’ tooling preferences, staffing constraints and profitability while taking responsibility for recovery work the cloud provider won’t perform. The source notes some practitioners “find it faster to stand up a new shell and rebuild it than try to gain access back into a compromised tenant,” which shifts the operational calculation toward having reliable, rapid restore workflows that can stitch identities and data back together in the correct order.

For IT leaders, the article argues recovery planning should be proactive, not improvisational: a platform that restores Microsoft 365 and Entra ID together “in a single workflow” reduces the risk that identity and the data it unlocks will come back out of sequence. For insurers and compliance officers, the source says cloud-to-cloud immutable backups are “increasingly written into cyber insurance and compliance requirements,” making such protections both a contractual and regulatory concern.

Conclusion: plan for recovery before the alarm sounds

The central takeaway from the reporting is straightforward and stark: Microsoft will keep services running, but customers remain responsible for ensuring their data can be restored to a known-good state after an incident. Closing the gap between availability and true cyber recovery means keeping immutable copies of tenant data outside the production environment, testing recovery workflows that reunite identity and data, and choosing platforms designed for fast, reliable restores. For MSPs and internal IT teams juggling SLAs, profitability and night-shift incident response, that preparation can be the difference between a recoverable outage and irreversible data loss.

Original story