Affordable Office 365 Backups with Synology Active Backup
When it comes to backups and Office 365, there are plenty of misconceptions in the industry. Yes, you do need to backup Office 365 data; No, it doesn’t have to cost you an arm and a leg. Synology’s Active Backup for Office 365 gives you backups without breaking your budget.
Synology reached to me and asked if I would be interested in reviewing their Active Backup suite. To help, they have supplied me with one of their latest generation devices a DiskStation DS920+. This is not a sponsored post and the thoughts within are my own.
Why Backup Your Office 365
Too many organisations and IT professionals believe that you do not need to perform backups of Office 365 data. The truth is, just like any other production system, you need to have a backup plan for this data.
Typically, backups are described as a copy of data that is taken and stored away from the original. A backup can be used to restore the original after a data-loss event. To be clear, backups are independent copies; they should be stored separately of the original data.
Microsoft doesn’t provide any services as part of Office 365 that fit this description. If you don’t believe me, just checkout their Office 365 compliance documentation (Microsoft O365 Mapping of CSA CMM v3.0.1):
Microsoft O365 Mapping of CSA CMM v3.0.1
People confuse backups for redundancy, particularly geo-redundancy that Microsoft provides with Office 365. Geo-redundancy involves replicating data between multiple sites, with the aim of ensuring that access to data is always available, even in the event of hardware or site failures. With replication, data deletion requests or data corruption will be replicated to each site. Replication doesn’t stop deletion or corruption; it doesn’t let you go back in time as there are no separate copies of the data.
People also confuse litigation holds and retention policies with backups. These controls allow you to specify how long data is held or retained by Office 365 even after a user deletes it. There are no separately stored copies of the data, for later restoration. If a file or message is corrupted, retention policies will simply define how long Office 365 keeps a copy of that corrupted piece of data.
Another consideration is compliance – everyone’s favourite topic. Most level and regulatory frameworks define a backup requirement or the ability to retrieve past data. Retention policies can help here, but backups are the only tool to ensure you truly meet your compliance requirements.
Synology Active Backup for Office 365
When you talk about backup products, Synology might not be the first vendor you think about. I am here to tell you needs to change. Synology’s Active Backup Suite is here to challenge the status-quo.
The Active Backup Suite comes as free packages that can be installed on any compatible Synology hardware. It offers a wide range of protection, including:
- Client PCs, servers, file servers and virtual machine hosts – with Active Backup for Business,
- Office 365 including Exchange, SharePoint and OneDrive – with Active Backup for Office 365, and,
- G Suite including Gmail and Google Drive – with Active Backup for G Suite.
The focus of this review is Active Backup for Office 365, but I encourage you to check out the rest of the Active Backup Suite.
Cost Effective Backups
I am impressed with how Synology has positioned itself in what could be considered a crowded solution space. They have positioned themselves as being cost-effective, by ditching the per-user licensing model of their competitors. All you need is a compatible Synology NAS and enough storage, and you are good to go.
I will admit, the licensing model grabbed my attention when Synology first contacted me. No per-user licensing, they must be crazy. As the Head of Information Technology at Telstra Purple, I spend a significant portion of my time navigating vendor licensing models. Most products in the Office 365 backup space make use of a per-user monthly or yearly subscription model, something that looks low cost for small user counts, but as you scale out, the cost can get out of hand.
I wanted to get a rough idea of the cost difference between Synology and one of its competitors. As I said, this is a rough estimate, but helps to show how Synology are positioning Active Backup for Office 365. In this example, I will be working with an Office 365 tenant that has 500 users, and I want to retain the backups for 7 years. Below are my estimates (in AUD).
| Active Backup for Office 365 | Competitor's Product | |
|---|---|---|
| User licensing | $0 | $10,000/year |
| Server | Synology DiskStation DS3617xs @ $3900 | Azure D4v3 @ $500/month |
| Storage | 12 NAS rated 10TB Disks @ $550/each | Azure Storage @ $2000/month |
| Total Costs | ||
| Yearly cost | $10,500 | $40,000 |
| Total cost over 7 years | $10,500 | $280,000 |
I realise this this isn’t the fairest of comparisons, with power, cooling and replacement hard disks have not factored into the Synology estimate. I have also assumed a fixed amount of Azure Storage consumption for the competitor. What should be clear is that the biggest factor on overall cost is the yearly per user licensing.
As someone who is responsible for maintaining an IT budget, I must admit, it would be hard to choose the more expensive option.
Easy to Configure Backups
From personal experience, enterprise backup solutions were always complicated to configure and maintain. I still have nightmares about troubleshooting backups on Exchange 2010! Due to this experience, I allocated plenty of time to setup Active Backup for Office 365, only to be surprised when it took all of 10 to 15 minutes. I was also impressed to see support for multiple Office 365 tenants.
Currently, Active Backup offers protection for OneDrive, Exchange Online (mail, contacts, calendar and online archive) and SharePoint sites. In the beta release, there is addition support for Office 365 groups. The only thing I really would like to see is support for Microsoft Teams chat and conversation history.
I really liked how you can specify if newly created Office 365 user accounts are automatically included in each backup tasks. This is a great touch as it reduces the amount of work required when onboarding new users, awesome for those forgetful system administrators.
My only disappointment when configuring backup tasks was how you specify data retention. Active Backup for Office 365 provides two options: keep all versions or specify how many days a copy should be kept. Every vendor has their own approach for specifying retention policies, and Synology isn’t alone with the all or number of days approach. I personally prefer how retention policies are specified in Azure Recovery Vaults. This issue isn’t a showstopper, but more fine-grained policies might allow for better storage efficiency.
Easy to Restore Content
Synology haven’t just made running backups easy, they also made it easy to restore content with an end-user accessible self-service portal. From the Active Backup for Office 365 Portal, users can choose to restore data that may have been deleted or corrupted, without the need for administrator involvement.
Providing self-service options to your users is a critical aspect to the success of any IT team. The simple option of allowing users to perform tasks, like restoring Office 365 files and content makes them feel empowered and most importantly, frees up your IT team to work on more important tasks. Self-service will make you and your users happy.
Unfortunately, I found the portal a little bit difficult to navigate. I wish the interface more closely resembled the Office 365 user interface, as that would have felt more intuitive. I felt the mechanism to switch between viewing mail, OneDrive, contacts and calendar items wasn’t obvious at first.
Synology recommends enabling single sign-on (SSO) with Azure Active Directory. This will allow users to connect to the portal using their Office 365 credentials, no need for separate accounts. This isn’t required, but I would expect this to be setup for production environments. If you wish to use accounts created on the Synology, just ensure that the email address matches between the Synology account and the Office 365 account.
Synology currently only supports one SSO provider, so if you are performing multi-tenant backups, you will need to consider which Azure AD you federate with. SSO is configured via Azure AD application registration, so you will not need Azure AD Premium licenses.
Overall Thoughts
| ✔ | Setup is simple. |
| ✔ | Support for user self-service data restoration. |
| ✔ | Support for multiple Office 365 tenancies. |
| ✔ | No per user licensing, subscriptions or renewals. |
| ❌ | No support for Teams conversation history. Currently supports OneDrive, Exchange (mail, contacts, calendar and online archives) and SharePoint sites. |
| ❌ | Retention policies are someone limited. |
| ❌ | Requires the purchase of hardware. |
I am really impressed by Active Backup for Office 365. Setting up Synology appliances and applications has always been very user friendly. The setup and restore experience are well designed and when integrated with Azure AD sign-on, provide end-users with self-service content restoration.
I believe the licensing model will be highly attractive to many organisations, even large enterprises; however the misconception that Synology’s market is home users, hobbyists and small businesses may result in many IT professionals to not thoroughly consider Active Backup for Office 365. Don’t fall for this misconception.
As someone who leads the internal IT team for a cloud first organisation, I can see the requirement to purchase Synology hardware a drawback. This could be a real blocker. Synology have some cloud offerings, perhaps their next step would be to offer Active Backup as a SaaS product.
I recommend that anyone supporting Office 365 environments to look at Active Backup for Office 365. It allows you to meet your organisations backup and data protection requirements as a cost-effective price point. I am and will recommend Active Backup for Office 365 to customers, clients, friends.
Active Backup for Office 365 is under active development, there are additional features and fixes already available in the public beta release.
I want to thank Synology for giving me the opportunity to work with DiskStation DS920+, it is a remarkable device that is very suited for IT professional and hobbyist use.
Mitigating the risks of IMAP credential stuffing attacks in Office 365
A recent Bleeping Computer article reported that email security company Proofpoint, had observed a massive increase in credential spraying attacks that target Office 365 and G Suite. These attacks leverage legacy email protocols (IMAP) and credential dumps to bypass the multifactor controls provided by these platforms.
A recent Bleeping Computer article, Multi-Factor Auth Bypassed in Office 365 and G Suite IMAP Attacks, reported that email security company Proofpoint, had observed a massive increase in credential spraying attacks that target Office 365 and G Suite. These attacks leverage legacy email protocols (IMAP) and credential dumps to bypass the multifactor controls provided by these platforms.
Now I am a bit sceptical of some of the numbers in the Proofpoint report, however I have seen other similar reports. I personally believe it is a safe assumption that most Office 365 and G Suite tenants have been targeted and that these attacks have successfully breached some of these tenants.
These attacks have been successful because:
- IMAP bypasses MFA (and some conditional access controls) on these platforms. This is due to the lack of support for MFA in the base IMAP protocol.
- The attackers have taken care to avoid potential account-lockouts. As a result, the attacks look like isolated failed logins and go unnoticed.
- MAP is an easy protocol to develop automated attacks against.
How can we protect our Office 365 tenants from these types of attacks?
There are three steps you can take:
- Disable IMAP and POP access to mailboxes, and,
- Disabling legacy authentication using an Exchange Online Authentication Policy, and,
- Disable legacy authentication using a Conditional Access Policy.
Each of these steps targets different behaviours, and as such, I believe you should put all of these controls in place.
Disabling IMAP and POP client access
The first step is to disable users access to their mailboxes using IMAP and POP. Why do this? To be honest, why would any of your users be using these protocols? With Outlook applications on Windows, MacOS, iOS and Android and third party applications that support modern authentication, I don’t see any need for users to be sticking to these legacy protocols.
Unfortunately, you need to disable IMAP and POP at a mailbox level, you cannot disable it at a tenant level. To disable these protocols, we can connect to Exchange online and then use the set-CASMailbox CMDLet. Remember you need to do this for all mailboxes!
Set-CASMailbox -Identity $EmailAddress -PopEnabled $false -ImapEnabled $falseThis could be included as part of your user automation processes.
Disabling legacy authentication using an Authentication Policy
You can find a great guide on doing this at Microsoft Docs, Disable Basic Authentication in Exchange Online.
Disabling legacy authentication protocols using a Conditional Access Policy
There is also a guide on Microsoft Docs, How to: Block legacy authentication to Azure AD with conditional access, that will help you set up a Conditional Access Policy that blocks legacy authentication protocols from use.
Enabling Mobile Device Management with Office 365
Microsoft recently announced that they would be including a Mobile Device Management (MDM) platform as part of Office 365. What this means is that organisations, both small and large now have an extremely easy and powerful MDM available to them, without any additional charge to their Office 365 licencing. Administrators can manage Android, iOS and Windows Phone devices, and enforce various corporate policies and standards.
To support the new MDM functionality, you will need to create two new DNS records in each of your Office 365 domains. I have updated the Posh-Office365CloudFlare script to support the creation of these two additional records. You can create these records via the -MDMEnable parameter.
The process for creating the entries is as simple as:
Register-Office365.ps1 -CloudFlareApiToken <token> -CloudFlareEmailAddress <email> -Domain <domain> -MDMEnable
Just a quick note, I am yet to fully test out the new MDM functionality as none of my existing tenants have enabled for it yet.
Kieran Jacobsen
Automating Office 365 deployments in CloudFlare
A few weeks ago, I wrote about Posh-CloudFlare, a PowerShell module I created for managing CloudFlare hosted domains. Since then, I was working on extending an Office 365 deployment, and realized that what was needed was a script which could automate the configuration of new domains. With that in mind, I developed a new PowerShell script, Posh-Office365CloudFlare.
Let's understand the process for the addition and configuration of a new domain for Office 365.
The process starts with the Office 365 Portal. We navigate to the Domains section, click the "Add Domain" button, and after ignoring the introduction, we proceed to step 1. This step starts with us entering our domain name, let's use our old favorite contoso.com. Now we will be asked to verify that we own this domain, either through the creation of a TXT record or an MX record. The typical method is to use is that of a TXT record, created at the root of our desired domain with a value something like "MS=mx********".
After we create the domain, and the wizard successfully sees the appropriate record, we will be allowed to proceed to the next step. Step 2 isn't one that I usually make use of. I typically don't want to modify my users email domains, nor do I want to add new users at this time. I skip this step and move straight on to step 3.
Step 3 starts with another quick introduction screen, and then we will be asked if we would like the DNS for this domain to be managed by Microsoft. Obviously, we are going to answer no and move on. Finally, we reach an important step, we are asked what we want to do with this domain. First, "Outlook for email, calendar, and contacts", or in other words, email; the second, "Lync for instant messaging and online meetings", which is kind of obvious.
If you select “Outlook for email, calendar, and contacts”, then we will be told to create the following records in contoso.com:
- MX - @.contoso.com - which points to contoso-com.mail.protection.outlook.com (priority 0)
- CNAME – autodiscover.contoso.com – which points to autodiscover.outlook.com
- CNAME – msoid.contoso.com – which points to clientconfig.microsoftonline-p.net
- TXT – @.contoso.com – which contains a SPF record
If you select “Lync for instant messaging and online meetings”, then we will need to create the following records for contoso.com:
- CNAME - sip.contoso.com - which points to sipdir.online.lync.com
- CNAME - lyncdiscover.contoso.com - which points to webdir.online.lync.com
- CNAME – msoid.contoso.com – which points to clientconfig.microsoftonline-p.net
- SRV - _sip._tls.contoso.com - with its appropriate port, weight, priority and target
- SRV - _sipfederationtls._tcp.contoso.com - with its appropriate port, weight, priority and target
Reviewing this list of records, we will notice that the only record that changes for each domain is the MX record. The record consists of the domain name we want to add, with dashes replacing the original dots in the domain name. As you can see in the above example, cotoso.com's MX record points to contoso-com.mail.protection.outlook.com, where as awesomecompany.net would point to awesomecompany-net.mail.protection.com.
What about some records that could actually help our users? What if I said we could redirect sub domains of our own to the Outlook Web Access page? Wouldn't it be awesome if a user entered https://mail.contoso.com into their browser, and ended up with the Outlook Web Access? This can be achieved by creating a CNAME record that points to mail.office.com. Let's have our script create entries for mail and webmail perform this redirection.
Now back to the script.
This was a simple script, it doesn't have any complex logic, it will need the following information:
- CloudFlare API Token and email address; this is obvious as we need to talk to the CloudFlare Client API.
- The domain name.
- Do we want to create mail records? Lync records or both?
This is a very, very simple script, we just need to have a set of New-CFDNSRecord calls, with various controls depending on what we require.
For example, creating the MX record is as simple as:
This script only took an hour or so for testing and development time, however there was quite a bit of effort directed to changes in the Posh-CloudFlare and the New-CFDNSRecord CMDLet. If you look at the diff's between the last few versions, you will notice the following changes:
- The CMDLet now accepts input from the pipeline (in this case via property name).
- Restructure the CMDLet into Begin/Process/End (required for proper handling of pipeline input).
- Implementation of parameter sets.
- Cleanup of the validation of parameters.
I added parameter sets to New-CFDNSRecord with the aim to remove the somewhat faulty validation that I had previously. Whilst this sounded, and looked like it was simple, it actually took a few tried to ensure that the CMDLet would function appropriately. This was really interesting and deserves its own post in the future.
Parameter validation was updated in all of the CMDLets to improve email address validation. Previously, validation consisted of testing for an "@" character. Now I am using a regular expression.
Finally, I have spent some time cleaning up the code, not just within New-CFDNSRecord, but across all of the CMDLets. I have been trying, where possible to use ISE Steroids to ensure that everything I right is neat and presentable; it is a fantastic resource.
My final thought on all of this journey is, why couldn't Microsoft have implemented something like this? Microsoft has integrated the process with a bunch of other DNS providers, including the likes of GoDaddy, Network Solutions, 1 and 1 and even Yahoo Small Business. Why can't it also look at CloudFlare?
You can find the finished script over at GitHub, at Posh-Office365CloudFlare, the script is called Register-Office365.ps1. I have included comment based help with examples.
Kieran Jacobsen