Restoring: the six-step guide
Source, selection, point in time, target, scope and review. Which targets are available per source type, which state to choose after a ransomware incident, and what a restore does not carry over.
A restore runs through a guided sequence of six steps: choose the data source, select what to restore, choose the point in time, choose the target, define the scope, review and start.
Which point in time to choose
Without a selection the most recent state is used. After a ransomware incident, the most recent state is the encrypted one. Choose a point before it, and when in doubt, earlier rather than later.
Where items can be written back
Targets depend on the source type, because Microsoft does not offer a way back everywhere.
Mailbox. Into the same mailbox, into another mailbox of the same account, or as a file. Writing back always creates a new folder named after the point in time; existing data is never overwritten and never placed back into its old folders.
Online archive. As for the mailbox.
OneDrive. Into the same or another OneDrive of the same account, or as a file. Here too a new folder with a timestamp is created. OneNote notebooks are exported as an .onepkg package.
SharePoint list. Exclusively as a new list on the original site, with the point in time in its name. The existing list remains unchanged.
Microsoft Teams. Exclusively as a new team with the point in time in its name, or as a file. Microsoft offers no way to write into an existing team.
Teams chat. As a file, or as a new team in which each conversation becomes its own channel. There is no way back into an existing conversation; this applies to all vendors.
Planner. Into the original plan, where existing tasks remain and the backed-up ones are added. Or as a new plan in the same group.
Group mailbox. Exclusively as a file containing the correspondence and its attachments. At Microsoft a post could only be created anew with today's date, and that would not be a restore.
Entra ID. Through its own page with a change plan and item-level selection, see Restoring the directory.
A target other than your starting point requires explicit confirmation.
Four-eyes principle
If approval is enabled, writing back requires the consent of a second authorised person. The approval is valid for 48 hours and can be used exactly once; after that it is spent, even if the run did not go ahead.
Approval is checked only when writing back into Microsoft 365. Export as a file is not covered by it.
What a restore does not carry over
- Nothing lands where it was. Even in "back to origin" mode a new folder with a timestamp is always created. This is deliberate: writing into existing folders could overwrite present data.
- A chat becomes channels, not a chat again.
- A group post cannot be written back.
- An archive mailbox accepts no writes at Microsoft; export as a file remains.
- The read state is carried over only if the corresponding additional consent has been granted.
Before every restore the guide states the limits of the chosen combination in plain words.
After starting
The start of a restore is notified, and that notification cannot be switched off. You follow progress under Restores; the outcome is in the audit log.
If the route leads to a file, continue with Export and retrieval.