Skip to main content
Valto — Keep ahead of tomorrow

Managed Services & Licensing

Backup & disaster recovery

Microsoft protects their platform. Getting your own data back is your responsibility, and most organisations find that out at the worst possible moment. Valto designs, implements and manages backup and disaster recovery across Microsoft 365, Azure and on-premises infrastructure. That means agreed recovery objectives rather than assumed ones, restores tested rather than reported as successful, and a written recovery plan your own team has been trained on. We start by establishing what is genuinely protected today, which is usually less than people expect.

Harddrive
Microsoft Solutions Partner

TRUSTED BY ORGANISATIONS LIKE YOURS

Mind
Greene King
Grosvenor
City of London logo
Chester Zoo
ABM
Human Appeal
John Deere
UKTV
Astrazenica
Money Supermarket
Princes
Sony
Shell
BBC
OVERVIEW

What Microsoft protects, and what is left to you

Most organisations believe their Microsoft 365 data is backed up. What they usually have is retention: recycle bins with a limited window, deleted item retention, and Microsoft's own replication protecting against their infrastructure failing. That covers Microsoft's responsibilities well. It does not cover yours. It will not help when a file was deleted four months ago and nobody noticed, when a departing employee cleared their mailbox, when ransomware encrypted a mapped library, or when somebody overwrote a document that mattered and version history had been turned off. The same applies to your infrastructure, with a different shape. Microsoft keeps Azure available. Whether your virtual machines, databases and file shares can be restored to a point in time you can live with depends entirely on how backup was configured and whether anyone has tested it. On premises, it depends on whether the backup that reports success every night has ever been restored from. Valto establishes what is genuinely protected today, agrees what your recovery objectives actually need to be, implements what is missing across Microsoft 365, Azure and on-premises systems, and then proves it works with regular testing. The last part is where most arrangements fall down, because a backup nobody has restored from is a plan rather than a protection.

What we protect

We establish what is protected today before recommending anything. In most reviews, part of the estate is covered better than expected and part is not covered at all.

Microsoft 365: Exchange, SharePoint, OneDrive and Teams

Mail, calendars, sites, libraries, documents, version history and the SharePoint sites underneath Teams, recoverable past Microsoft's own retention windows. Teams is the one most people assume is covered because it looks like a separate product, and usually is not.

Azure workloads

Virtual machines, managed disks, databases and file shares, with backup policies, retention tiers and geo-redundancy set against how important each workload actually is.

On-premises servers and infrastructure

Physical and virtualised servers, file shares and line-of-business systems, with on-premises or cloud storage depending on your recovery objectives and constraints.

Disaster recovery planning

Identifying your critical systems and data, agreeing recovery objectives, and producing a written recovery plan aligned to how your business actually operates rather than to a template.

Failover and rapid recovery

Failover to a secondary site, Azure-based recovery and virtualisation-based options, designed around how long you can afford to be without each system.

Testing, monitoring and refinement

Regular restore and failover testing, with the recovery process improved from what the testing finds, plus continuous monitoring of backup success and failure.

Training your team on their part in it

A recovery plan only works if the people in it know what they are responsible for. We train your team on their roles so a disaster is an execution rather than a discovery.

How our backup and DR service works

Establish what is genuinely protected

We assess your infrastructure, your current data protection measures and any existing recovery strategy, covering what is backed up, how far back it goes, what is excluded, and whether a restore has ever been tested. You get a written position on what is covered, what is exposed and what it would take to close the gap.

Why work with Valto on backup and recovery?

We start by telling you what you already have

Some of your estate is probably better protected than you think and some is not protected at all. The review establishes which, before anybody buys anything.

Recovery objectives agreed, not assumed

How much data you can afford to lose and how long you can be without each system are decisions we work through with you, by workload, rather than applying one policy to everything.

Restores tested, not just reported

A backup that reports success and has never been restored from is a hypothesis. We test regularly and improve the recovery process from what the testing finds.

Your team is trained on the plan

A recovery plan nobody has rehearsed is a document. We train the people who would have to execute it so that a disaster is an execution rather than a discovery.

Microsoft 365, cloud and on-premises from one place

A single view across Microsoft 365, Azure and physical infrastructure, rather than three arrangements with three suppliers and three gaps between them.

Backup and retention treated as different things

A retention policy keeps content you are obliged to keep. A backup gets back content you have lost. Conflating them is why a lot of organisations believe they are covered.

Expertise
Microsoft 365, cloud and on-premises specialists
Certainty
Restores tested, not assumed
Readiness
A plan your team has rehearsed
Power Apps Envisioning Workshop

WHAT WE TYPICALLY FIND

Where organisations turn out to be less protected than they believed

Very little of this is negligence. It is the gap between what Microsoft protects and what people assume Microsoft protects, and between having a backup and having a plan.

  • Microsoft 365 assumed to be backed up, when what exists is retention with a time limit
  • No backup of Teams at all, because it looks like a separate product
  • Backup reporting success daily, with no restore ever tested
  • Three separate arrangements for Microsoft 365, cloud and on-premises, with gaps between them
  • Whole SharePoint sites deleted, taking their content with them, past the recovery window

How we deliver backup and DR projects

From establishing what is genuinely protected today, through to tested recovery against objectives you have agreed and a plan your team knows.

  1. Security assessments
    1

    Risk assessment

    Establish the current position

    We assess your infrastructure, existing data protection and any current recovery strategy: what is backed up, how far back, what is excluded, and whether a restore has ever been tested. Documented, so you have a baseline.

  2. SharePoint Consultant hosting a requirements workshop
    2

    Objectives

    Agree what you can live with

    Critical systems identified, and recovery point and recovery time objectives agreed by workload rather than as one number. These are business decisions and we work through them with you.

  3. Woman working on laptop
    3

    Design

    Match protection to the objectives

    Backup methods, storage location, retention tiers, immutability and failover approach set against the objectives and against what your insurer or customers require, rather than against product defaults.

  4. People working on computers
    4

    Implementation

    Configure and verify

    Deployed across Microsoft 365, Azure and on-premises systems, then verified with an initial test restore rather than declared complete when the first backup reports success.

  5. Valto team at Microsoft London
    5

    Plan and train

    Write it down and rehearse it

    A written recovery plan covering procedures, responsibilities and escalation, and training so the people in it know their part before they need to.

  6. 6

    Manage and test

    Monitor, retest, refine

    Continuous monitoring, regular restore and failover testing, the recovery process improved from what testing finds, and reporting you can pass on. Reviewed as the estate changes, because backup configured once drifts.

We're one of the UK's few Microsoft partners to hold all Microsoft Solution Partner designation badges, across all Solution Partner designation pathways. For backup and recovery that matters because protecting a Microsoft estate properly means knowing what Microsoft already does, what it does not, and where the boundary sits. The people configuring your protection are the same specialists who run your Microsoft 365 tenant and Azure infrastructure, so backup reflects how your environment is actually built rather than being applied to it from outside.

WHY ORGANISATIONS CHOOSE VALTO

Microsoft Solutions Partner
Apps on a phone

CONNECTED, ACROSS MICROSOFT

Retention, archiving and backup are three different things

A Purview retention policy keeps content you are obliged to keep and prevents its deletion. An archive moves content you rarely need somewhere cheaper. A backup gets back content you have lost. Organisations routinely have one of the three and believe they have all of them. Valto brings together expertise across Microsoft 365, Azure, Purview, security and on-premises infrastructure, which means we can tell you which of the three you actually have, where they overlap, and where the genuine exposure is. Sometimes the answer is more backup. Sometimes it is a retention policy, a version history setting, an immutable copy, or moving data off laptops. The result is protection matched to what you are actually worried about, rather than a product applied to everything.

Questions, answered plainly

Practical answers on what Microsoft does and does not protect, how far back a recovery can go, and whether a backup alone is enough.

Not in the way most people assume. Microsoft protects their own platform: infrastructure, availability and resilience against their systems failing. What they provide for your content is retention, meaning recycle bins and deleted item retention with a limited window, plus replication. Past that window, deleted content is gone. Recoverability of your own data from your own mistakes, a departing employee, ransomware or a deletion nobody noticed is a customer responsibility under Microsoft's shared responsibility model.
No, and it is the most common misunderstanding we come across. A retention policy prevents content being deleted before a date you have set, which serves a compliance purpose. A backup lets you retrieve content you have lost. A retention policy will not restore a site somebody deleted last year, and a backup will not satisfy a regulator asking about your retention schedule. Most organisations need both and believe they have both when they have one.
That depends on the retention you choose and the workload, and it is one of the decisions we work through with you rather than applying a default. The question underneath it is how long a loss could plausibly go unnoticed, because that is the window that actually matters. Four months is not unusual for a rarely used file share.
They are two business decisions: how much data you could afford to lose, and how long you could afford to be without a system. Usually called recovery point and recovery time objectives. Most organisations have never been asked, and the answers differ by workload, since a finance system and a marketing file share do not need the same protection. Agreeing them is what turns backup from a purchase into a design, and it is why some recovery plans promise something the technology cannot deliver.
Yes. Physical and virtualised servers, file shares and line-of-business systems, with on-premises or cloud storage depending on your objectives and constraints, alongside Microsoft 365 and Azure. Most organisations we work with have some of each, and the gaps tend to be between them rather than inside any one of them.
Acronis is our backup platform of choice, covering Microsoft 365, cloud and on-premises workloads from one place. Where a different product genuinely fits your requirements better, we will tell you rather than making it fit.
No, and the assumption that disaster recovery is an enterprise concern is one of the reasons smaller organisations are more exposed. The consequences of losing your data do not scale down with headcount, and the solutions do: what changes with size is the recovery objectives and the cost, not whether you need a plan.
Backup is duplicating your data so you can retrieve it when the original is lost. Disaster recovery is your ability to keep operating through a serious disruption and restore essential systems quickly, covering strategy, technology and procedure, documented as a plan. Backup is part of disaster recovery rather than a substitute for it: it will get your data back, but not necessarily get you working again within a timeframe your business can absorb.

FREE BACKUP & RECOVERY REVIEW

Find out whether a restore would actually work

Whether you're answering an insurance questionnaire, have realised Microsoft 365 is not covered the way you assumed, have a recovery plan nobody has read, or simply want to know how far back you could recover, start by establishing the current position.

  • Microsoft 365, cloud and on-premises

    One view across the whole estate, rather than three arrangements with gaps between them.

  • Objectives agreed, not assumed

    How much data you can afford to lose and how long you can be without each system, by workload.

  • Tested, and rehearsed

    Regular restore testing, documented, and training so your team knows their part before they need to.

  1. 1
  2. 2
What is your enquiry about?*