How backups work for managed clients — and how restores usually go

Backups are supposed to be boring. This page is the calm map of where your files are protected, what you can usually put back yourself in about a minute, and when to open a ticket instead — including what to do if something looks like ransomware.

Managed backup is a subscribed service. It only applies to customers who have purchased managed backup with The I.T. Experience. Managed IT support alone does not automatically include it. If you are not sure whether your organization subscribes, ask us before assuming a system is covered.
Managed backup is a subscribed service
Coverage varies by agreement. Even among subscribers, not every computer and every Microsoft 365 tenant is configured identically. If you are unsure whether a specific PC, folder, or mailbox is included, ask us. Guessing wrong is how work ends up only on a Desktop that was never in scope.
Three layers of protection: self-serve, Microsoft 365 retention, managed backup for subscribers

The 30-second version

Think in three layers:

  1. Self-serve — Recycle bin and Version history in OneDrive, SharePoint, and Teams. Start here for one file you deleted or overwrote. See Recovering a deleted file or an earlier version.
  2. Microsoft 365 retention — Extra safety inside Microsoft 365 when your tenant has it configured. We usually handle these restores.
  3. Managed backup (subscribers only) — Copies we take of the systems that keep the business running (servers and, where your backup subscription includes them, workstations and/or Microsoft 365 data). This is what we use for bigger recoveries. If your organization does not subscribe to managed backup, this layer does not apply — start with self-serve OneDrive recovery and contact us for options.

If files are opening as gibberish, you see a ransom note, or a whole team lost access at once — skip self-serve and contact us.

One file in OneDrive / Teams / SharePoint? Try Recycle bin or Version history first. That path is faster than a ticket when only you are affected and the file lived in Microsoft 365.

Managed backup vs OneDrive versions

These get mixed up often. They are both useful — and they are not the same thing.

  OneDrive / SharePoint / Teams Managed backup
What it is Recycle bin, version history, and (for your own OneDrive) a short whole-library rollback Copies we take of systems covered by your agreement
Who restores Often you, in a browser or File Explorer Us, from a ticket
Best for “I deleted / overwrote this document” Whole folders, servers, many machines, older recoveries, ransomware-shaped events
Not a substitute for Saving work in the right place Saving every personal USB stick or random Downloads folder
Plain English: OneDrive version history is a great undo button for day-to-day mistakes. Managed backup — when you subscribe to it — is the safety net for bigger or older problems, and for systems that are not OneDrive at all (file servers, shared drives, and other systems we back up for you).

If the file lived on a mapped network drive or company file server rather than in OneDrive/Teams/SharePoint, the self-serve Recycle bin steps do not apply. Open a ticket and we will recover from the right layer — see also when the OneDrive article says the same thing under “Was it actually a OneDrive file?”

What is typically in scope

We speak carefully here on purpose. Exact coverage is defined by your backup subscription and agreement, not by this article.

Managed backup only applies if your organization subscribes to it. For those subscribers, it is aimed at the systems that keep the business running. Depending on that agreement, that can include:

  • Servers and shared company data
  • Workstations or laptops — coverage varies by agreement. Ask us what is included for your organization.
  • Microsoft 365 mailboxes, OneDrive, or SharePoint — coverage varies by agreement. Ask us what is included for your tenant. (Self-serve Recycle bin and Version history still apply to your own Microsoft 365 files either way.)

You do not need to “run” a backup job yourself. Our monitoring watches for failures. If a backup is unhealthy, that is on us to catch — not something we expect you to check every morning.

Saving to Desktop or Downloads is not automatically “backed up forever.” On many managed computers we redirect or sync known folders into OneDrive — but that is not universal, and a USB drive you plugged in once is almost never in scope. When in doubt, ask which folders we expect you to use for important work.

We keep product console screenshots out of this article on purpose so the advice stays accurate when tools change. What matters on your side is how to ask for a restore.

What you can usually fix yourself

For a single document in your OneDrive, a Teams channel, or SharePoint:

  1. Restore from the cloud Recycle bin, or
  2. Right-click the file → Version history and bring back an earlier copy

Full steps (including Teams → Open in SharePoint, online-only files, and the whole-OneDrive rollback) live here:

Recovering a deleted file or an earlier version

Try that path before opening a ticket when:

  • Only you (or one shared library) are affected
  • The file lived in OneDrive / Teams / SharePoint
  • It went missing recently enough that Recycle bin / versions still apply
Worth remembering: the two commands that solve almost all day-to-day file oopses are Recycle bin in your browser (file gone) and Version history on the right-click menu (file still there but wrong). Neither one needs a ticket to try.

How to request a restore

When self-serve is not enough — or you are not sure — open a ticket. Do not wait until after you have rebuilt the file from memory.

Submit a support request · email [email protected] · phone (603) 505-4290

Put “Restore request” (and the system, if you know it — e.g. “OneDrive file”, “shared drive”, “server folder”) in the subject.

Details that speed us up

Copy/paste this into the ticket when you can:

  1. What — file name(s), folder path, mailbox, shared drive, or “whole PC / whole server”
  2. Where it lived — your OneDrive, a Teams/SharePoint library, a mapped drive letter, a server share name
  3. When it was last good — approximate date and time (include time zone if you are traveling)
  4. Who is affected — just you, a team, or the whole company
  5. Urgency — e.g. “blocks invoicing today” vs “nice to have this week”
  6. What you already tried — Recycle bin, Version history, search for a moved folder
  7. Anything else that helps (screenshot of an error, affected drive letter, etc.)
Restore request checklist — tell us these six details
The more precise the path and the “last good” time, the faster we can find a clean copy. File recovery is mostly a search problem; those details are the search terms.

What a restore usually feels like from your side

  • Single file / small folder: often returned beside the original or into a recovery folder once we have the details — typically same business day for straightforward requests, size and layer permitting.
  • Mailbox item or calendar: we confirm the date range and where it should land (same mailbox vs export).
  • Server, many machines, or a larger event: we give you a short plan and an ETA rather than silence. Larger restores are paced so we bring back clean data, not a second copy of the problem.

Exact timing depends on which backup layer holds the copy, whether we can restore during business hours, and how large the recovery is.

You do not need to babysit a console. We will tell you when the files are ready and where to look.

Ransomware basics (plain English)

Ransomware is software that encrypts files and then demands payment. On a work computer it can look like:

  • Files suddenly will not open, or open as nonsense
  • Strange new extensions on many files at once
  • A text file, pop-up, or desktop wallpaper telling you to pay

Stay calm. Looking this up and calling us is the right move. Speed and a clean recovery path matter more than diagnosing the brand of the malware yourself.

If you think you are looking at it

  1. Stop clicking around to “try one more folder” or opening every encrypted file.
  2. Disconnect from Wi‑Fi or unplug the network cable if you can; leave the machine powered on.
  3. Contact us immediately — phone (603) 505-4290 is best when minutes matter — or follow Reporting an IT Security Incident.
  4. Do not pay. Do not run random “decryptor” tools from the internet. Do not wipe or reinstall the PC before we have a chance to collect what we need.
A ransom note is an incident, not a DIY weekend project. Do not pay. Do not call a number from the note. Call us at (603) 505-4290 or submit a support request marked urgent. Early calls are how small events stay small.

Our goal is to restore from a clean managed backup (and to confirm the path that let it in — often email). If the story started with a suspicious message you already interacted with, also see I already clicked a phishing link or entered my password — what to do next once the urgent “stop and call” steps are done.

Paying does not guarantee your files come back, and it funds the next attack. We do not recommend paying. Tell us what you see; we will plan recovery from backups and secure the environment.

What backups are not

  • Not a substitute for saving work in the right place (OneDrive / SharePoint / the file server you were shown)
  • Not a personal Time Machine for every USB drive someone plugged in once
  • Not the same thing as “I emailed the file to myself” or a PST on a flash drive
  • Not instantaneous magic for every minute of every day — we restore from the copies we have, at the retention your agreement includes
  • Not something you need to “kick off” before leaving for the weekend
Email “backup” ≠ a PST on a USB stick. If you need a mailbox item recovered, open a restore ticket with the approximate date — do not export mail to removable media as a habit.

Testing and proof (what we handle)

You do not need to run test restores yourself. We verify managed backups on a schedule as part of how we support managed clients. If a backup job fails, our monitoring is meant to catch it.

If your leadership team wants a plain-language summary of what is covered for your company, ask us — that conversation belongs with your account contact and us, not in a public guess on this page.

What not to do

Skip these — they burn time or make recovery harder:
  • Do not assume Desktop / Downloads / a USB stick is covered without asking
  • Do not wait a week to report a missing important file — recovery windows close
  • Do not pay a ransom, “fine,” or gift-card demand from a page or note
  • Do not download decryptors or “cleanup” tools advertised by the same pop-up
  • Do not wipe the PC, reinstall Windows, or reimage unless we ask you to
  • Do not blast “we’ve been hacked” emails to All Staff before you have talked to us — use the incident reporting path
  • Do not keep working in folders that look half-encrypted “to see what still opens”

Need a restore or not sure what’s covered? [email protected] · (603) 505-4290 · Submit a support request

Was this article helpful?