SaaS backup is a service that copies data out of cloud applications, such as Microsoft 365, Google Workspace and other software-as-a-service tools, into separate storage so it can be restored if it is deleted, corrupted or encrypted. The SaaS provider keeps its service running and offers built-in recovery features, but those features live inside the same service and account as your data and are designed for different jobs: recycle bins and version history for recent mistakes, retention policies and holds for compliance. A SaaS backup gives you copies kept outside the application, on your schedule. It can also isolate those copies from a compromised admin account, but only when backup administration and deletion are protected by separate credentials or roles, or by immutable retention; some products share your identity provider or rely on delegated tenant permissions, so check how yours is set up.
At a glance
- SaaS backup copies data from cloud applications to storage separate from the application itself.
- It complements the provider’s built-in recycle bins, versioning and retention features, which live inside the application and are built for recent mistakes and compliance rather than full restores.
- Microsoft 365 and Google Workspace are the most commonly protected, but many services cover other apps too.
- It typically supports restoring single items, whole mailboxes or sites, or everything as of a point in time.
- It is often sold per user, as a standalone service or as part of a wider backup service.
What problem it solves
Many companies assume that moving email and files to software as a service (SaaS) means backup is handled. In practice, the standard SaaS subscription focuses on keeping the platform available; some providers sell backup as a separate paid add-on. Recycle bins and version history help recover recent mistakes, but only within limited windows. Retention policies and holds can keep content for long periods, even indefinitely, depending on feature, license and configuration, but they are designed to preserve content for compliance, not to restore it quickly into place; they cover what the policy names; and they sit inside the same service and under the same admin accounts as the data. Provider terms generally leave responsibility for your content with you.
That leaves real gaps. A user deletes a folder and nobody notices until after it has aged out of the recycle bin. An administrator removes a departed employee’s account and, if no retention policy or hold covers it, their mailbox goes with it. A compromised account or ransomware encrypts synced files, and the damage spreads across the tenant. A sync tool error overwrites shared files. SaaS backup keeps a separate copy outside the application. How well that copy survives an attack depends on whether it is administered and protected separately from the accounts that were compromised.
How it works
Connection. The backup service connects to each application through the interfaces the provider offers, using an authorized account or application permission, and discovers users, mailboxes, sites, drives and other data.
Scheduled copies. It copies data on a schedule, often several times a day, and keeps versions according to your retention policy. Copies are stored outside the SaaS application, in the backup provider’s cloud or in storage you control, depending on the service.
Protection. Good services encrypt copies, separate backup administration from the SaaS admin accounts, and offer immutable backup or deletion safeguards, though features and defaults vary.
Restore. You can search and restore a single email or file, a whole mailbox or site, or a user’s data as of a point in time, either back into the application or as an export.
Lifecycle. Many services let you keep backups for departed users after their licenses are removed, which can save license costs while meeting retention needs.
When it matters for buyers
- When you have moved email and files to SaaS. This is the point where backup responsibility often falls through the cracks.
- When cyber insurance renews. Insurers may ask how cloud data is backed up, not just servers.
- When staff leave regularly. Keeping departed users’ data without paying for active licenses is a common reason to buy.
- When legal or retention needs grow. Separate, searchable copies can help with requests for historic data.
- When applying the 3-2-1 rule. The provider’s copy is one copy; the 3-2-1 backup rule calls for more, with one kept elsewhere.
Questions to ask vendors
- Which applications and which data types within them do you back up, and what is not covered?
- How often are backups taken, and how long are versions kept?
- Where are backup copies stored, and are they separate from our SaaS tenant and its admin accounts?
- Are backups protected from deletion by someone with our admin credentials?
- How quickly can we restore a whole mailbox, site or the entire tenant, and is bulk restore throttled by the SaaS provider?
- How are departed and inactive users priced?
How it differs from BaaS
Backup as a service (BaaS) is the broader category: a provider supplies and runs backup for servers, virtual machines, databases, endpoints and often SaaS data too. SaaS backup is the part focused on data that lives in cloud applications, protected through those applications’ interfaces rather than through agents on your own systems. Some buyers get it as a feature of a wider BaaS or data protection as a service (DPaaS) offering; others buy it on its own, especially when nearly all their data already lives in SaaS. Our Microsoft 365 backup overview covers the most common case.
