In this section we review 9 leading Microsoft 365 Backup solutions using vendor documentation, including Afi, AvePoint, Commvault (SaaS), Cove, Datto, Druva, Keepit, NinjaOne, and Veeam VDC.
All of the backup services can recover basic M365 workloads. Where they differ is fidelity: whether SharePoint returns with its structure and metadata, whether Teams messages are recovered at all, and whether the Exchange Recoverable Items folder and email metadata are protected.
Exchange Online
Microsoft Limitations
Microsoft keeps the Recoverable Items folder in the mailbox's hidden area: "The Recoverable Items folder resides in the non-IPM subtree of each mailbox". It has seven subfolders — Deletions, Versions, Purges, Audits, DiscoveryHolds, Calendar Logging, SubstrateHolds. Graph's folder list names only one of them, recoverableitemsdeletions.
In addition, there is no Graph endpoint for mailbox folder permissions; the Outlook tasks API stopped returning data in 2022; Notes and Journal have no first-class resource.
Tier 1: Highest property-level evidence and export options
Commvault and Afi offer the deepest mailbox fidelity. Afi preserves metadata and properties including: folder identity, message participants, dates, classifications, MIME when available, file and inline attachments, item attachments, reference-attachment link metadata, historical versions, and read/unread flag. On recovery, new objects receive destination identifiers, existing objects expose only writable properties. Commvault recovers encrypted (S/MIME and Purview) messages, but its documentation gives less evidence about raw MIME, custom properties, attachment subtypes, and server-controlled fields.
Afi and Druva provide the widest range of data export options (PST, MBOX, EML, VCF, and ICS). However, Druva's Recoverable Items coverage is limited to Deletions and Purges, and it does not support item attachments, reference attachments, recurring calendar data, task due-time semantics, task step completion, and task step order.
Tier 2: Material exclusions
AvePoint excludes “Deleted Items folder and the Junk Emails folder ... from the backup for better performance”; customers are required to contact support to include them. The primary-mailbox PersonMetadata folder is excluded; the vendor does not specify preservation of MIME, transport headers, extended properties, source IDs, change keys, created times, or last-modified times.
Veeam offers granular in-place restores with production comparison, and backs up In-Place and Litigation Hold item folders by default (VDC gates preservation-hold restore out of its Foundation and Advanced plans). However, calendar sharing permissions are not collected, and the documentation does not provide evidence of custom extended properties, item-attachment nesting, reference-attachment behavior, source IDs or change keys.
Cove has the longest exclusion list (no tasks, contact lists/attachments, unaccepted invites, color categories). Datto “does not backup Deleted Items” and is unable to restore in place (mail lands in a timestamped restore folder).
MS Teams
Microsoft Limitations
Microsoft Graph makes chatMessage.from (the sender identity on a message) writable only when "...sender of the chat message. Can only be set during [migration]."
A vendor either drives the Import API in migration mode (a Graph state that lets historical messages be written back), or it re-posts messages as an ordinary user, which produces the fidelity gap below.
Tier 1: Author and timestamp preserved
Afi provides the highest message fidelity: backup covers public, private and shared channels with reactions, mentions, importance flags, adaptive cards and system messages. Recovery to a new team fully restores the post/reply hierarchy and timeline; messages keep (uniquely) their original authors and sent dates plus attachments and formatting. One-to-one, group and meeting chats are backed up (deleted chats included) but only available for preview/download-only (this limitation is applicable to all vendors).
Tier 2: Lost message metadata
The vendors in this group recover messages as live posts, but authored by the backup account and stamped with the restore date.
Keepit restores posts and replies; restored messages are posted by the backup service account, the timestamp reflecting restore time, not send time. Reactions and channel permissions are not restored; shared channels come back standard.
AvePoint, Commvault, and NinjaOne use the same repost model and report similar limitations; in AvePoint "the conversation time in the restored HTML file is UTC time", "Reaction: Like — Unsupported", and "The Edited status of a post or reply cannot be kept".
Cove can recover posts, but it restores only into a new "[Restored]" team; private channels come back public, guests and General-channel/group settings are lost.
Tier 3: Messages are not restored as messages
Veeam Data Cloud for Microsoft 365 exports posts to a file of the HTML format, creates a separate tab in the original channel and attaches the HTML file to this tab. It also omits "One-on-one and group posts" from backup.
Similarly, Druva restores conversations as HTML files under the Files tab of the team. Reactions also are not restored.
Datto: "Conversations cannot be restored. However, you can export and download conversations", plus a hard ceiling of "1000 is the maximum number of replies that can be backed up for a Teams message".
SharePoint Online
Microsoft Limitations
A SharePoint Online (SPO) item carries system columns (Created/Modified timestamps, Author/Editor identities), custom columns, version history, a content type (a reusable bundle of columns and settings), and permission assignments.
Microsoft Graph API has significant restrictions in its ability to write some of this metadata. E.g. it marks createdBy, lastModifiedBy and their timestamps read-only on list items, and "updating the ModifiedBy (Editor) or CreatedBy (Author) field for a document in SharePoint using the Microsoft Graph API is not directly possible". Graph also omits column properties. As a result, backups may fail to preserve validation formulas, or fully reconstruct hyperlink and managed-metadata columns. Graph also offers "Read-only support for site resources (no ability to create new sites)", which leads to some vendors being unable to rebuild a deleted site.
Graph-only products are therefore limited in their ability to reconstruct SPO metadata, as opposed to high-fidelity backup services that use REST/CSOM to restore SPO data, because it allows vendors to overcome many restrictions embedded in Graph API.
Tier 1: Metadata, IDs
Afi and AvePoint provide the strongest explicit coverage. Afi is the only vendor ensuring ID preservation: recovery "preserves the original file/folder structure and metadata, including custom metadata column values, modification dates, and file/folder/item IDs", and it can provision new sites on recovery.
AvePoint has a close scope: per-column matrices mark every standard column type as restorable, plus site columns, content types, permissions and page content. At the same time, Avepoint states that “The content type applied to the list item cannot be kept after restore”, and classic publishing recovery changes the site into a communication site.
Tier 2: Content-centric
Commvault's coverage matches Afi's and AvePoint's coverage but certain restored list items with attachments can have discrepancies in metadata values such as Modified By and Modified Time.
Keepit has broad backup coverage (sites, subsites, libraries, lists, pages, permissions, site columns, content types, selected site settings) but has restore gaps including managed-metadata columns, and Created by/Modified by list columns. Veeam has similar limitations: on restore, Created By becomes the restoring account, site owners/group members are not restored, and full-site restore needs a pre-existing target site.
Others
Druva restores site permissions/people-groups, content types, site columns, and content-associated labels, but item-level column fidelity is unstated, classic sites cannot be restored to a new site, purged classic sites cannot return to the same site, and deleted sites of either template cannot be restored in place, leaving several common disaster scenarios with no supported path.
NinjaOne cannot restore directly to site pages NinjaOne restore documentation, and site/wiki/web-part pages are skipped on restore download only. Cove excludes lists, pages, metadata values, and previous versions Cove limitations. Datto states that “SharePoint metadata is not backed up”, everything restores out of place into a timestamped "SaaS Protection Restore" folder.
Lesser workloads
Coverage of other Microsoft 365 data types generally reflects vendors' attention to the core data sources discussed above.
Keepit and Afi offer the broadest support for Power Platform. Afi protects Power BI, Power Apps, Power Automate, DLP policies and tenant settings, with per-object version history and native-format export (PBIX, PBIR, RDL, ZIP). Afi doesn't provide automated restore options and administrators need to follow manual steps to restore data. Keepit has a slightly narrower Power Platform coverage, but offers partial automated recovery options.
Afi, AvePoint, and Keepit provide the best overall currently documented OneNote recovery, especially when storage metadata and possible in-place object-ID retention matter: they recover native OneNote notebook packages, not just loose .one files. Several products protect only notebook files or cannot reconstitute a unified notebook. Cove and Veeam explicitly call out OneNote as unsupported.