The Practical Guide to Backing up your Hybrid Cloud Environment
Transcript
Hello everyone and welcome to my session. During today's event, we're going to be talking a little bit about the practical guide to backing up your Hybrid Cloud Environment. My name is Theresa Miller and I'm a principal technologist with Cohesity. Before we dive in, I want you to think about your infrastructure and your environment's configuration for backups. What most enterprises are dealing with today is they have on-prem environment, and because of their cloud-first strategies, they also have cloud environments. And so our goal today is to talk a little bit about what you're doing with on-prem.
I want you to think about that, right? You have solid set-up, backup, and protection environment in place for your on-prem. But the options for the cloud can be a little bit different and each cloud provider may offer you something different. And so there may be some inconsistency as it relates to how you're backing up that data and even understanding what your options are. So today, I'm going to focus on cloud, more specifically Microsoft Office 365, as well as Microsoft Azure, what they offer you natively, and what you should be considering holistically for your entire environment in terms of needs, SLA's, recovery time objectives, recovery point objectives, and more.
So, keep those things in mind as we take this journey together today. In terms of our overview, we're going to start out with data responsibility. I'm going to share with you some real world examples where I had data become lost, in one case not recoverable and in another it was. And help really drive home where that responsibility lies. Is the cloud provider going to help you with that recovery or not? We're then going to talk about, from a very technical perspective, what you get natively with Office 365 for data protection.
So again, we're going to get a little technical here. I'm going to show you where the settings are, the different consoles, so you really know what your options are. And then we're going to shift gears into Azure native protection. Understanding what you have for opportunities to leverage the Microsoft solutions to protect your data. And then we're going to close things out with really trying to think differently and take a closer look at how we choose a solution for our environments as we have on-prem and cloud, essentially the hybrid deployment.
So let's go ahead and take a look. So who is responsible for the data? You're a cloud customer and you're putting data in the cloud. Before you answer, I want you to consider these things. Did you know that every business will fall victim to ransomware every 11 seconds by next year? According to Cybersecurity Ventures predictions. Personally, the more people I talk to, the more people I hear of having ransomware breaches. And so I think that it really comes down to it's not an if, it's more of a when.
And I think that these statistics solidify that. So keep that in mind. How are you going to protect yourself from ransomware? Now according to "Our World in Data" there were almost 300 reported national disasters in 2018. The numbers last year were similar and as we move into 2020, we're off to a pretty good start. There have been tornadoes, earthquakes, snowstorms, you name it. Natural disasters happen all the time. Where are data centers? How are we protecting that data?
When it comes to email, in 2019 phishing emails increased 109% over just two years prior. And phishing, of course, is out to seek your data. But sometimes, they include links that take you to malware and ransomware and infected sites. And so if phishing is that much higher, we are all at risk. And then consider the cost element. A data disaster can cost $5,400 per minute, according to Gartner. That's a lot of money per minute and I know most enterprises do not want to sacrifice that level of spend on something that could have been prevented or easily recovered from.
So as we talk about data responsibility, I wanted to share some stories that I experienced from the real world, again, to kind of help understand the different elements. So, in this particular case, I was using Office 365 and first level support could not find this email message that was critical to an executive from over a year ago. It just could not be found. Essentially, it was inadvertently fat-finger deleted several months back and nobody realized it. We're going to dive into the nitty-gritty of this but the long story short is that, with the options available in the cloud, you could only go so far back.
And a decision was made not to put policy in place to keep data for a long time either. And so what that left us with was the inability to get this message back. So of course you have to look at the lessons and opportunities to fix things, and so we learned that without any form of backup or policy in place, we were not able to get the message back and that was time to redo things and get things to a place where we could recover that data.
Another situation that I went through was I had go to your subject-matter expert for a virtual machine, right? The application analyst had a virtual machine get corrupted after they ran Windows Updates. And so what we learned very quickly was that the virtual machine didn't have a backup when they called in for help. They're like how do I get my machine back? And it didn't have a back-up because when we dive into some of these details further, you'll find out and I'll reiterate then that by default, a virtual machine in the cloud doesn't actually have backup enabled.
So, if there's no backup enabled, how do we get this machine back? Well, no backups, corrupt machine, all we had left was to call support. And what we found out is that, thankfully, after 24 hours, we were able to get the machine back online, but keep in mind this was a production system. So yes, we're happy, we've got the machine back, that we can now put back in production and continue our work flow with. But it was down for 24 hours.
So that's significant. A lot of enterprises can't bear that type of downtime on a production system and it was hard enough for the enterprise I was working with at the time. So the lessons learnt here are yes, support was able to recover the virtual machine. Now, note that with each cloud provider, the guarantees on this are different. There were no guarantees in this case, but thankfully it was recoverable. But more importantly, know what your recovery point and recovery time objectives are as you're making decisions about whether or not to backup the machine and how fast you want things back because the downtime and impact can cost you money.
We talked about the Gartner statistics around the cost per minute. Now, of course, that will vary per application but it can be significant. And so one more thing on data responsibility. We're going to break this down in a different way. You as the cloud customer, you have enterprise data. And here are the risks that you need to protect your enterprise data from. If user errors or insider threats eliminate data, your cloud provider's not going to get that back for you.
If there are security issues such as ransomware or phishing or viruses or malware, your cloud provider cannot get that back for you. And you're also responsible for application usage. How that application is used. So if we take Office 365 for example, and the process used to do calendering makes a calender appointment disappear, you are responsible for getting that calendar appointment back. Your cloud provider will not. So you may be thinking, well what are they responsible for? If they're not going to help me get my data back, what are they responsible for?
Well, let's take a look. They're responsible for platform issues. So, back in infrastructure failures. If we stick with Office 365, you are never managing a server. They are responsible for all the backend server infrastructure. So there's an application level failure on that backend, so for example, if you use Outlook Web App, and Outlook Web App goes down, they're responsible for getting that back. And then they're also responsible for high availability and that can vary. The high availability, there are some options you can pay for over and above what counts natively, but it is their responsibility to make sure your system stays online, and every call provider will have different SLA's for this.
So data protection is shared. If the data is for your enterprise, you are responsible and the cloud provider will keep your infrastructure online. So now let's take a look at Native Office 365 data protection. As we move into this section, I want you to be paying attention to the different methods that you're using to protect your data. So let's take a look. So method number one. Okay, I promise this will be technical as well. So, any time I use PowerShell in this section of the presentation, the assumption is that I ran all of these commands to connect to my environment in order to do them.
So this is a great slide to keep handy and make sure you have available, and I also have a resource of a Microsoft doc that also highlights some of these commands as well. So any time you see that. And then the other element you're going to see in this section is that I am going to leverage the GUI for some things and show you where those things are. So, when it comes to data protection, one of the elements that you have for recovering data is the plain old deleted items.
So your trash bin in Outlook will allow you to get your data back and then, of course, is very user-driven. Now, if you are not leveraging E3 or higher from a subscription perspective, you will be limited to 30 days. Again, if you're E3 or higher, you can set it as far up as you need. In fact, you can go unlimited. And here's where you do that. You're going to go into the Exchange Admin Center, go to Compliance Management, and you're going to configure two elements.
You're going to configure a Retention Tag for deleted items and a Retention Policy. And this is going to help you keep your E3 and up subscriptions at an unlimited level or whatever retention you'd like to set in place. And we do that through two screens. So, one, this is where you set the Retention Tags. Again, we're in the Exchange Admin Center in Compliance Management to get to this. And here is the other element, the Retention Policy. Again, in the same general area that the Retention Tag was set.
And this will help you keep some of that data longer. There's also a deleted item recovery section and this is also found right in Outlook. So you can empower your users, essentially, from Outlook Web App. If you click on deleted items, and you go to recover deleted items from this folder, you can choose, essentially, the item you want to recover. So what I have here in my image is that I'm showing you my deleted item recovery and I have a couple messages in there that I could click restore on and recover, if I wanted.
So both of those options were very user specific. Now, you as an admin. For that deleted item recovery, for your users to be able to recover anything more than 14 days in Office 365, you're going to need to go in and connect to PowerShell and you're going to run a command. So if you want to do this per user, here's your command. Or, if you want to do it for your entire Office 365 Exchange Online Mailbox Set, then you're going to leverage this command instead.
The max you can set this to is 30 days, keep that in mind. If you are an exchange on-prem administrator, you know that you could go much further out than 30 days. I know personally when I would use this for granular recovery and empower my enterprise users to recover their own messages, we would oftentimes go out as far as 90 days. With Office 365, 30 is the limit. And there's one more thing here. If you want to make sure that globally, going forward, onward and forever, that your users get the 30 days, so when you add new users, you're going to actually need to set this PowerShell command instead.
So you have a few different options for addressing this, and can set at whatever mailboxes you need to at whatever retention you need. And there's the resource for you. If you want to find the Microsoft article on that. One more option that Exchange administrators or Exchange Online administrators can leverage for keeping data longterm is legal hold. So, first thing, you must have Exchange Online Plan 2 or higher. So essentially, that is part of Enterprise E3 and E5 subscriptions, so if you have those you have this option.
And they must have the Discovery Management Role to be able to pull the data out. So, anyone that you're going to allow to pull data out as a legal hold must have that role. Now how do we do this? What we do is we set, in the Exchange Admin Center, under Compliance Management, In-place Discovery and Hold. So we're going to go ahead and pull that up here. And essentially, you're going to go ahead and create this hold. And so, you can do this type of legal hold for all mailboxes or you may just do it for specific users.
So let's say you have C-Level users that you just want that extra layer of protection- remember, I shared my own story about how I had a C-Level that we couldn't get the mailbox data back for, so having an In-place legal hold may be a good option for you. So you can see, though, that there are quite a few steps to get this set up. Again, it's kind of in a separate area and you'll have to put some thought in it to be able to retain that data.
So some of the considerations for the legal hold and how you leverage this to get your data out are these things. So it can take a lot of time to search. In fact, it can take hours. You can only export it to a pst, and you must manually import that data back in. And then, to be able to get the search, you need to do a new case. And there's literally a ten-step process to even complete this and get the pst file out.
And again, keep in mind this can take hours. So, if you're not sure of what recovery point you're going to get back from running this or the recovery time, hours, to get a message back may not be suitable for your enterprise. And leveraging this option is not likely for you. Now I'm going to shift gears over to OneDrive and Sharepoint specifically. So you do have the ability to get your data back out of regular deleted items for up to 93 days, your deleted files and folders.
So again, this is user-specific activity, your users can just pull their data back. Here is a site in which I can show you here that they would just leverage the recycle bin. Now, there's also the site collection recycle bin. This is more of an administrative level function where files can be emptied by the user/administrator and sites can be restored by the administrator as well. And so where do you find this? You find it by going to the SharePoint site, recycle bin, settings, site content, et cetera, et cetera, until you get here.
And then, the emmet can pull the data back for the user. And then, last but not least, Microsoft has the ability and will keep a 14 day backup of SharePoint files not in the recycle bin. So you can open a support case, but there's not guaranteed SLA. So if you call in, even though there's that 14 day window, there's still a chance that they're not going to be able to get it back for you. For OneDrive and SharePoint, you also have the ability to leverage version control.
If version control has been enabled, you do need to turn this on. You can roll back a file to a previous version. OneDrive can go back to a point in time, as far back as 30 days. It does not include deleted items, and it will only recover corrupted or infected files. So how do we set this up if we don't have Versioning for SharePoint in place? We go to the SharePoint document library, you go to Settings, Library Settings, Version settings.
So here's that Settings wheel. And essentially we dive into the console and we're able to set that so we can pull those back. Here's the Versioning settings. So you have about three, four clicks to get there. What about OneDrive? Well, if you're going to do Versioning for OneDrive, you actually need to go back to classic OneDrive to set this and you go to the Settings wheel, Library Settings, and Version Settings. So you can see that from a control perspective with Office 365, it's not like having that on-prem console where you have one location to backup and recovery according, to do backup and recovering according to your SLA's.
As your native protection, so Azure has a little bit more of a backup element to what they offer you natively. And so let's take a look at that. Azure Native Data Protection option one is to set this up manually when you set up the Virtual Machine. So that actually would have helped in the case where I was talking about. I had a Virtual Machine that was not set up by me in any way, shape, or form. We had some (inaudible) experts in the enterprise that were allowed to create their own servers and set up their own applications, and essentially, they didn't know how to take this step.
So how do we do that? com, we choose Virtual Machines on the left-hand side of our screen, we click the Virtual Machine, see here. We choose backup and then we can put whatever policy we need in place, daily or weekly backup is your option. And then you can also configure retention, if you need to keep these for a longer period of time, you can set that right here. Another option for protecting your Virtual Machines, it actually can happen in a little bit more of an automated fashion, is leveraging PowerShell.
NET, you're going to open up PowerShell as administrator, you're going to verify some of these settings, and make sure that you have everything configured. Once these configuration settings are complete then you can start working with PowerShell. And do take note of the resource doc at the bottom here. That can be handy and a good reference for what I've shared with you here. So with PowerShell, Microsoft does have a backup script available to you for completing this type of work. So, what it's going to do is it's going to create a Recovery Services Vault with Geo-Redundant Storage.
And it's going to allow for a daily backup with 30 day retention and creates a recovery point and retains it for 365 days. So essentially, the script leverage is all of these commands and then some. Now, in terms of actually getting started with this script, again, note the resource at the bottom because that's where this lives, you're going to have to edit some of the global variables that are already there in the pre-created script to align with what you see here. Like you need to give it a vault name, you need to give it your resource group name, your location, and register the Recovery Services provider via the command at the bottom and register it as AzResourceProvider to get this running.
So there's a little bit of work involved but ultimately at least there is a pre-created script if you're interested in using PowerShell to get this running and it will work if you add new machines. So it will, ongoing, if you don't want to have to think about that manual element of adding backup to machines this will help with it. So when it comes to Azure, again, you have some options. They're considered true backup options but you are managing it in multiple different ways.
In fact, there's one more thing I do want to call out about PowerShell scripts. From a PowerShell script perspective, one of the things that I find, even though Microsoft wrote the script for you, PowerShell scripts do change over time and PowerShell commands change over time and people change over time. And so what I do find is oftentimes I will inherit a script that somebody else wrote and find that eventually, after years, I can't even edit it because something will break. So do also consider that risk when you're making a decision on whether or not to automate this with PowerShell.
So, we're going to wrap things up here in just a couple minutes. We're going to talk a little bit about how to choose a solution for hybrid deployments where we have the on-prem, we have the cloud, and the native options won't help our enterprise meet our SLA's, our Recovery Point Objectives, our Recovery Time Objectives. And even the configuration of it and the management of it isn't centralized. So how do we do that? Well, I'm challenging you to think a little bit differently.
When you're choosing a data protection option, find something that will protect both your on-prem and cloud environments from a single console. It's going to really simplify things, it's going to actually take and allow people to have more for other work that they may need to be taking care of, and it will reduce your training cost if you have one solution. Consider the automation element. Some of what I shared with you natively, you do get automation from the Microsoft site on, but some of it's not.
And actually, most of it wasn't. So what automation options do you need to be successful? Do you want a single console? A single pane of glass for all of your management. Even for other clouds. If you could manage everything from one single pane of glass, would that be beneficial to you? What are your Recovery Point ObjectiveS? Is waiting hours to get an email message back or a mailbox back okay? Especially if you have multiples, or if there's a mass issue, is that okay?
To wait hours and then not even know what point in time you're going to get? So that actually ties both of these points together, the Recovery Point and the Recovery Time. What are your external risks and how are you going to manage that recoverability? Ransomware, viruses, accidental data deletions, they happen all the time. What are you going to do to make sure your data's protected? And this one is also interesting. Do you have the ability to isolate your current state of your Office 365 data for legal and compliance and have people asked for this?
And with native Office 365 options, you cannot take a copy of that data and isolate it for legal and compliance reasons. So having a solution that can do that would go a long way. And then what if you change your mind about the cloud? Do you have access to your data for exit planning? Sometimes those decisions get made. And so with that, I just want to thank you so much for your time today. If you have any questions, feel free to let me know and feel free to reach out and we'll have that conversation to make sure that you have all the information you need to make the best decisions about your backup and recovery for the long-term, regardless of where the data is, on-prem or in the cloud.
Thank you. (upbeat music)