What gets backed up: scope, cadence, retention, storage
Selection rather than discovery, backup cadence per source type, retention period, storage tiers with and without object lock, your own storage target, and the reasons a source is not backed up.
Discovery is not backup
Conbool discovers the sources in your Microsoft tenant on its own. A source is backed up only once it has been selected under Users or Groups.
That is the most important sentence on this page. A newly created mailbox that nobody selects is the most common cause of a protection gap, and it only surfaces when damage is done. If you add people regularly, review the selection regularly too.
Backup cadence
Five cadences are available:
| Cadence | Interval |
|---|---|
| Weekly | once a week |
| Daily | once a day |
| Economical | every 12 hours |
| Standard | every 6 hours |
| Frequent | every 4 hours |
The cadence applies to the whole tenant but does not affect all sources equally.
Frequently changing sources run at the chosen cadence: mailbox, online archive, group mailbox, OneDrive, SharePoint files. Only changes are transferred there, so a frequent cadence costs little.
Rarely changing sources run once a day regardless: SharePoint lists, Teams, chat, Planner, Entra ID. There is no delta comparison for them; every run reads the full state.
The promised recovery point must match the cadence: the verification interval may be at most half the cadence, otherwise the verification run reports a gap that is none.
Retention
The retention period determines how long a backed-up state is kept.
Note the current operating state: the daily deletion run operates as a dry run. It determines what has expired and removes nothing. Backed-up states are retained beyond the configured period. The product points this out at the setting itself.
Storage
Three tiers, switchable per tenant:
Standard. Deletable at any time. This deselects immutability: a compromised account or an operating error can destroy source and backup alike.
Immutable. Not overwritable for the duration of retention. How far that holds against an attacker with valid credentials depends on the storage target.
Compliance. As immutable, additionally locked against Conbool. Only on written request.
A change of tier applies exclusively to future backups. States already written keep the property they were written with.
Where the backups are held
By default in Cloudflare R2 object storage within its EU jurisdiction. For heightened data sovereignty requirements a tenant can be switched to the object storage of STACKIT GmbH & Co. KG in region eu01 (Germany); contact support for that.
Your own storage target. You can register your own S3-compatible target. You then take responsibility for its operation, location, availability and backup. Whether immutability holds there depends on the provider: not every S3-compatible store implements an object lock, and without one the tier is a statement of intent with no technical effect.
Why a source is not backed up
The module breaks down every unprotected item by reason:
| Reason | Meaning |
|---|---|
| Not yet selected for backup | discovered but not selected |
| Above the seat count, unlicensed | more accounts than seats ordered |
| Excluded by the customer | excluded, costs no seat |
| Excluded by a rule | a rule applies |
| Switched off manually | somebody switched it off |
| Room or equipment mailbox | not selected |
| No longer present in Microsoft | the source is gone |
| Deleted under Article 17 | deleted on request |
| Created during a restore | a result, not a source |
| No route to this data source | a known gap at Microsoft |
| Not in the backup, no reason recorded | unexplained, report to support |
The first two are the most common and both are fixable.