1 00:00:00,086 --> 00:00:01,166 Imagine this. 2 00:00:01,226 --> 00:00:05,426 You're in the middle of a really important conversation in Microsoft teams. 3 00:00:05,846 --> 00:00:08,576 You spend several minutes typing up a response that 4 00:00:08,576 --> 00:00:10,406 will finally make your point. 5 00:00:10,826 --> 00:00:14,246 But the moment you hit enter the message disappears. 6 00:00:14,636 --> 00:00:15,476 And it turns out. 7 00:00:15,476 --> 00:00:17,666 So did everyone else's responses? 8 00:00:18,176 --> 00:00:23,696 Then you find out that every single conversation in Microsoft, 365 is gone. 9 00:00:24,326 --> 00:00:29,456 That's what happened to 145,000 KPMG employees, right in 10 00:00:29,456 --> 00:00:30,716 the middle of the pandemic. 11 00:00:31,196 --> 00:00:35,876 The Microsoft 365 admin was trying to delete a single user's chats 12 00:00:36,146 --> 00:00:40,406 when they actually deleted the entire company's data instead. 13 00:00:41,276 --> 00:00:45,536 And today's episode, we'll dive right into this jaw-dropping data disaster 14 00:00:45,746 --> 00:00:50,126 and see how it serves as a powerful reminder of the importance of backing 15 00:00:50,156 --> 00:00:52,376 up your cloud and SAS environments. 16 00:00:52,886 --> 00:00:56,846 We'll be discussing how Microsoft retention policies are not backups. 17 00:00:57,086 --> 00:00:59,096 This story proved my point. 18 00:00:59,696 --> 00:01:03,446 This episode is the latest in a series of cloud disasters. 19 00:01:03,746 --> 00:01:06,506 Companies that lost everything because they misunderstood 20 00:01:06,506 --> 00:01:08,096 how backups work in the cloud. 21 00:01:08,936 --> 00:01:14,486 We've already covered some major cloud vendors like AWS, Google, and OVH. 22 00:01:14,816 --> 00:01:16,346 Now it's, Microsoft's turned. 23 00:01:16,826 --> 00:01:21,416 If you hear this story and still think you don't need to back up Microsoft 365. 24 00:01:22,106 --> 00:01:23,576 I just don't know what to say. 25 00:01:24,566 --> 00:01:26,336 Hi, I'm W, Curtis Preston. 26 00:01:26,366 --> 00:01:27,236 AKA Mr. 27 00:01:27,236 --> 00:01:27,806 Backup. 28 00:01:28,106 --> 00:01:31,616 30 years ago, my employer lost their purchasing database. 29 00:01:31,856 --> 00:01:34,196 When it turned out, my backups were broken. 30 00:01:34,736 --> 00:01:37,136 I vowed that would never happen to me again. 31 00:01:37,226 --> 00:01:41,816 And now I try to do the same for those who read my books and listen to my podcast. 32 00:01:42,266 --> 00:01:47,756 I want to turn you the unappreciated backup admin into a cyber recovery hero. 33 00:01:47,996 --> 00:01:50,186 This is the backup wrap up. 34 00:02:03,277 --> 00:02:04,147 W. Curtis Preston: Welcome to the show. 35 00:02:04,717 --> 00:02:07,177 I'm your host, w Curtis Preston, AKA, Mr. 36 00:02:07,177 --> 00:02:10,177 Backup, and with me, I have what I hope to be. 37 00:02:10,507 --> 00:02:15,457 My personal non-ad advisor on taxes 38 00:02:16,462 --> 00:02:18,127 Prasanna Malaiyandi: Is it that time of year, Curtis? 39 00:02:18,967 --> 00:02:20,137 W. Curtis Preston: is that time of year. 40 00:02:20,797 --> 00:02:24,397 Um, although, although I have to say I have. 41 00:02:25,422 --> 00:02:27,607 I I, this will be a complicated year, right? 42 00:02:27,607 --> 00:02:28,837 Due to a variety. 43 00:02:29,017 --> 00:02:30,457 A variety of things, right? 44 00:02:30,457 --> 00:02:35,947 The interesting year of employment and non-employment and contractor 45 00:02:35,947 --> 00:02:37,507 work that I did last year. 46 00:02:37,997 --> 00:02:40,397 So let me get, are your taxes like already done? 47 00:02:40,887 --> 00:02:41,947 Prasanna Malaiyandi: Uh, no comment. 48 00:02:45,582 --> 00:02:45,872 W. Curtis Preston: Okay. 49 00:02:46,367 --> 00:02:49,967 I just, you just seem so put together with this whole tax thing that I 50 00:02:49,972 --> 00:02:52,307 figured that by now you'd be done 51 00:02:52,652 --> 00:02:55,202 Prasanna Malaiyandi: so I, I was just waiting for the last of the paperwork, 52 00:02:55,202 --> 00:03:00,602 but I am one of those crazy people who sort of pre-plan everything. 53 00:03:00,602 --> 00:03:01,172 So, 54 00:03:01,262 --> 00:03:01,552 W. Curtis Preston: Yeah. 55 00:03:01,652 --> 00:03:03,647 You got spreadsheets and stuff. 56 00:03:03,842 --> 00:03:07,052 Prasanna Malaiyandi: so usually I know more or less where I'll land 57 00:03:07,052 --> 00:03:10,862 based on pay stubs and it's just the final bits of like interest and 58 00:03:10,862 --> 00:03:12,362 dividends and other things like that. 59 00:03:13,397 --> 00:03:15,587 W. Curtis Preston: You probably wouldn't be sleeping at night if you're in 60 00:03:15,647 --> 00:03:18,372 my situation right now because I'm. 61 00:03:20,147 --> 00:03:22,307 Prasanna Malaiyandi: well, yeah. 62 00:03:22,367 --> 00:03:22,517 Yeah. 63 00:03:22,517 --> 00:03:23,387 I don't know how you do that. 64 00:03:23,387 --> 00:03:28,487 I, so I should say that 99.99999% of the people are like you, 65 00:03:30,567 --> 00:03:31,922 W. Curtis Preston: I think, I think you're right. 66 00:03:32,162 --> 00:03:32,522 Yeah. 67 00:03:32,522 --> 00:03:38,252 In fact, in fact, I know based on my work with, uh, Intuit back 25 years 68 00:03:38,257 --> 00:03:42,302 ago, that like they were saying, if I recall correctly, it was like 69 00:03:42,302 --> 00:03:47,522 something like 90% of their business on TurboTax occurs within like the 70 00:03:47,552 --> 00:03:49,682 last three days before April 15th. 71 00:03:50,792 --> 00:03:51,786 Prasanna Malaiyandi (4): Doesn't surprise me. 72 00:03:51,946 --> 00:03:54,535 One challenge too is there's a lot of fraud. 73 00:03:55,195 --> 00:03:57,655 Prasanna Malaiyandi: So someone takes your social security number files. 74 00:03:57,655 --> 00:03:58,975 A fake tax return. 75 00:03:58,975 --> 00:04:00,205 Gets the refund. 76 00:04:01,015 --> 00:04:03,475 W. Curtis Preston: that's, that is really hard to recover from. 77 00:04:03,475 --> 00:04:05,385 Yeah, you know what else is real hard to recover from? 78 00:04:06,105 --> 00:04:06,395 Prasanna Malaiyandi: What? 79 00:04:06,747 --> 00:04:10,227 W. Curtis Preston: deleted data in a SaaS provider that you don't have a backup of. 80 00:04:12,207 --> 00:04:13,167 See that segue? 81 00:04:13,377 --> 00:04:14,547 You're proud of that segue. 82 00:04:14,607 --> 00:04:14,847 Look at 83 00:04:14,867 --> 00:04:15,107 Prasanna Malaiyandi: good. 84 00:04:16,177 --> 00:04:20,197 W. Curtis Preston: So this will be a part of our continued series on 85 00:04:20,197 --> 00:04:21,607 why you should back up the cloud. 86 00:04:22,267 --> 00:04:25,957 And you know, the cl there, there's a bunch of different parts of the cloud. 87 00:04:26,047 --> 00:04:30,817 Uh, today we're gonna be talking about a, a SaaS provider, possibly 88 00:04:31,992 --> 00:04:33,937 of the biggest SaaS providers, 89 00:04:34,052 --> 00:04:35,436 Prasanna Malaiyandi (4): I think they're one of the most valuable 90 00:04:35,436 --> 00:04:37,326 companies in the world right now. 91 00:04:37,791 --> 00:04:39,711 W. Curtis Preston: So that would be Microsoft. 92 00:04:40,221 --> 00:04:47,781 And I remember in the, you know, my days at Druva, this was what 93 00:04:47,786 --> 00:04:52,521 we saw as like one of the biggest greenfield environments because hardly 94 00:04:52,526 --> 00:04:54,831 anybody backed up Microsoft 365. 95 00:04:55,066 --> 00:04:57,441 Prasanna Malaiyandi: don't need to back up Microsoft 365 Curtis, 96 00:04:58,371 --> 00:04:58,881 W. Curtis Preston: Right? 97 00:04:59,031 --> 00:04:59,481 Right. 98 00:04:59,541 --> 00:04:59,901 Prasanna Malaiyandi: you reach 99 00:05:00,111 --> 00:05:00,261 W. Curtis Preston: Uh. 100 00:05:00,261 --> 00:05:01,701 Prasanna Malaiyandi: strangle me through the video. 101 00:05:02,481 --> 00:05:06,801 W. Curtis Preston: Yeah, and, and the thing was, it was, it was super 102 00:05:07,101 --> 00:05:13,461 difficult for me as a person who has dedicated their career to backups. 103 00:05:13,971 --> 00:05:22,761 I really don't understand the people that have migrated to a SaaS provider 104 00:05:22,761 --> 00:05:25,791 have migrated any portion of their. 105 00:05:26,781 --> 00:05:31,221 IT infrastructure to some type of other provider of any kind, whether it's a, 106 00:05:31,221 --> 00:05:40,251 you know, I, a s, past SaaS, whatever, and didn't check this box, right? 107 00:05:40,551 --> 00:05:45,531 Didn't ask how does backup and recovery work there? 108 00:05:45,861 --> 00:05:46,221 Right? 109 00:05:46,221 --> 00:05:50,661 What's the thing that didn't look in the service agreement, didn't do any 110 00:05:50,661 --> 00:05:53,511 testing of any backup, let's delete. 111 00:05:54,111 --> 00:05:57,051 Something and then restore it and, right. 112 00:05:57,051 --> 00:06:01,611 I, I like, I mean, I, I've known for a long time that people hate backup. 113 00:06:01,611 --> 00:06:01,941 Right. 114 00:06:01,941 --> 00:06:03,801 Nobody, nobody wants to do 115 00:06:03,981 --> 00:06:05,241 Prasanna Malaiyandi: I am sorry Curtis. 116 00:06:05,931 --> 00:06:06,261 W. Curtis Preston: yeah. 117 00:06:06,351 --> 00:06:07,581 Nobody, yeah. 118 00:06:07,611 --> 00:06:09,471 Nobody wants to be the backup person. 119 00:06:09,891 --> 00:06:11,631 Uh, that's how I got my job. 120 00:06:11,631 --> 00:06:14,661 That's how I got my first job, was the, you know, Ron Rodriguez didn't 121 00:06:14,661 --> 00:06:15,891 want to be the backup guy anymore. 122 00:06:15,891 --> 00:06:17,181 And so that's how I got my job. 123 00:06:17,631 --> 00:06:17,901 Right. 124 00:06:17,901 --> 00:06:20,571 And that's how, that's how many of our listeners got their jobs. 125 00:06:21,681 --> 00:06:23,631 Uh, and it's how. 126 00:06:24,516 --> 00:06:27,546 Much of the cloud migration has happened, right? 127 00:06:28,146 --> 00:06:34,356 It's people move to something like Microsoft 365, and I do know for a fact 128 00:06:34,746 --> 00:06:41,256 that some Tams technical account managers at Microsoft 365 have uttered words to 129 00:06:41,256 --> 00:06:44,106 the effect that they don't have to worry about backup, and that's one of the 130 00:06:44,106 --> 00:06:47,046 reasons that they should migrate to 365. 131 00:06:47,466 --> 00:06:48,546 They're, they're wrong. 132 00:06:48,666 --> 00:06:49,896 They don't do it in writing, 133 00:06:51,021 --> 00:06:55,011 Prasanna Malaiyandi: This isn't unique to Microsoft 365 a SaaS or path, 134 00:06:55,191 --> 00:06:58,131 because do you remember back in the day with virtual machines, right? 135 00:06:58,131 --> 00:06:59,661 And VMware, right? 136 00:06:59,661 --> 00:07:02,211 They had the same message as well, right? 137 00:07:02,216 --> 00:07:05,991 And it wasn't until people were like, Hey, I'm now using this for 138 00:07:05,991 --> 00:07:09,831 production workloads and I really should care about how I back it up. 139 00:07:10,161 --> 00:07:14,691 And then that spurned sort of, okay, Veeam came along along 140 00:07:14,691 --> 00:07:16,161 with other backup vendors, right? 141 00:07:16,161 --> 00:07:17,841 Figuring out how to optimize it and make it better. 142 00:07:18,621 --> 00:07:20,241 But the initial ones you never had backups. 143 00:07:21,366 --> 00:07:21,666 W. Curtis Preston: Yeah. 144 00:07:21,666 --> 00:07:23,766 Backup never leads the charge in anything. 145 00:07:25,506 --> 00:07:25,746 Right. 146 00:07:26,316 --> 00:07:31,656 Um, and, but, but it's still, it's still depressing to me sometimes. 147 00:07:31,656 --> 00:07:32,046 Right. 148 00:07:32,526 --> 00:07:37,206 And, and in this case, there are people, I can think of one particular person 149 00:07:37,206 --> 00:07:40,596 I won't mention in my name, but I can think of one particular person that is a 150 00:07:40,836 --> 00:07:48,276 fellow book author that, you know, just really doesn't seem to see the need. 151 00:07:48,576 --> 00:07:54,156 To backup 365, even in his blog post about the incident that 152 00:07:54,156 --> 00:07:55,416 we're gonna talk about today. 153 00:07:56,106 --> 00:07:59,886 He said, you know, some people will probably tell you that this is an 154 00:07:59,886 --> 00:08:04,086 example of why you need to back up Microsoft 365, but I wanna tell you 155 00:08:04,086 --> 00:08:07,386 that even if you had backups, uh, that wouldn't have helped in this case. 156 00:08:07,386 --> 00:08:10,776 And he's right, but doesn't change the 157 00:08:10,971 --> 00:08:11,261 Prasanna Malaiyandi: Yeah. 158 00:08:13,056 --> 00:08:15,906 W. Curtis Preston: So enough with the preamble. 159 00:08:16,221 --> 00:08:17,661 What are we talking about here? 160 00:08:17,661 --> 00:08:25,551 What happened back in uh, 20, you know, August of 2020, what happened? 161 00:08:26,556 --> 00:08:28,776 Prasanna Malaiyandi: Isn't that right around the pandemic, Curtis, 162 00:08:29,976 --> 00:08:31,416 where aren't we all locked down? 163 00:08:31,716 --> 00:08:32,316 Not going 164 00:08:32,391 --> 00:08:33,531 W. Curtis Preston: we were all, yeah. 165 00:08:33,651 --> 00:08:35,751 So while we were all locked down, 166 00:08:36,336 --> 00:08:36,666 Prasanna Malaiyandi: Yeah. 167 00:08:37,566 --> 00:08:38,256 So. 168 00:08:38,421 --> 00:08:39,621 W. Curtis Preston: of little companies. 169 00:08:39,741 --> 00:08:43,851 Prasanna Malaiyandi: so this was a large, very, very, very large 170 00:08:44,421 --> 00:08:50,631 company called KPMG, which is a consulting slash auditing firm. 171 00:08:50,691 --> 00:08:51,381 They do both, 172 00:08:51,701 --> 00:08:52,051 W. Curtis Preston: Right, 173 00:08:52,311 --> 00:08:57,171 Prasanna Malaiyandi: and uh, they decided one day, Hey, I'm going to 174 00:08:57,171 --> 00:09:03,861 go change a retention policy for my Microsoft teams for a particular user. 175 00:09:05,286 --> 00:09:05,376 W. Curtis Preston: right. 176 00:09:05,541 --> 00:09:08,001 Prasanna Malaiyandi: And they went and made that change. 177 00:09:08,031 --> 00:09:13,701 And apparently they didn't realize it affected all users. 178 00:09:13,701 --> 00:09:18,141 And by the way, that small company you're talking about, it's like 145,000 people, 179 00:09:19,271 --> 00:09:20,946 W. Curtis Preston: You know, 45,000 people 180 00:09:21,111 --> 00:09:22,461 Prasanna Malaiyandi: And so it. 181 00:09:22,986 --> 00:09:28,176 So it impacted the retention for those 145,000 people. 182 00:09:28,176 --> 00:09:32,616 And so all these folks who are basically like, you know, auditing 183 00:09:33,006 --> 00:09:38,736 companies and have a bunch of sensitive chat messages and other things. 184 00:09:38,916 --> 00:09:39,186 Yeah. 185 00:09:39,186 --> 00:09:40,416 All those messages went byebye. 186 00:09:41,931 --> 00:09:43,461 W. Curtis Preston: Yeah, just poof. 187 00:09:44,586 --> 00:09:48,516 And I'm sure that they reached out. 188 00:09:48,516 --> 00:09:51,606 I mean, we don't, it's not in the story, but I am absolutely sure 189 00:09:51,606 --> 00:09:56,076 that they reached out to Microsoft, said, is there anything you can do? 190 00:09:56,376 --> 00:09:58,266 And the answer is, uh, no. 191 00:09:58,836 --> 00:10:03,306 Because what you experienced is a feature, not a bug. 192 00:10:03,351 --> 00:10:03,621 Prasanna Malaiyandi: yeah. 193 00:10:04,116 --> 00:10:04,356 W. Curtis Preston: And 194 00:10:04,356 --> 00:10:05,376 the, the, go 195 00:10:05,511 --> 00:10:06,291 Prasanna Malaiyandi: no, go finish. 196 00:10:07,836 --> 00:10:12,576 W. Curtis Preston: The true irony of this is that the feature that they were using. 197 00:10:14,256 --> 00:10:20,856 That resulted in the deletion of data is the feature that people, including the, 198 00:10:21,006 --> 00:10:27,066 the guy to which I was referring, they pointed this feature as a substitute 199 00:10:27,156 --> 00:10:30,126 for backup, that you should use this fe. 200 00:10:30,156 --> 00:10:35,016 That if you had, if you properly use this feature, you wouldn't need backup. 201 00:10:36,126 --> 00:10:38,406 But apparently if you improperly use the. 202 00:10:41,031 --> 00:10:41,301 Prasanna Malaiyandi: Yeah. 203 00:10:41,481 --> 00:10:45,456 So maybe Curtis, why don't you talk a little bit about the 204 00:10:45,456 --> 00:10:47,936 feature itself and what it does? 205 00:10:49,131 --> 00:10:49,401 W. Curtis Preston: Yeah. 206 00:10:49,401 --> 00:10:52,221 So the feature that we're talking about is retention policies, 207 00:10:52,311 --> 00:10:54,981 and they are complicated. 208 00:10:55,431 --> 00:11:00,441 They're, the last time I checked, if you went and looked at the, 209 00:11:00,441 --> 00:11:05,511 the justice feature in the documentation, there's 25 pages of 210 00:11:05,511 --> 00:11:08,151 documentation on this one feature. 211 00:11:08,691 --> 00:11:16,131 Uh, you know, that, that Microsoft 365 has, and basically what it's designed 212 00:11:16,131 --> 00:11:25,041 to do is to, in general, the idea is to make sure that things that should 213 00:11:25,046 --> 00:11:33,171 be around are around and subsequently things that shouldn't stay around, don't. 214 00:11:33,921 --> 00:11:34,251 So. 215 00:11:35,721 --> 00:11:40,311 A typical retention policy might be 90 days. 216 00:11:40,671 --> 00:11:48,801 We set a retention policy on email 90 days, which means that after 90 days, what 217 00:11:49,311 --> 00:11:56,661 sent email a received email of any kind, again, based on the policy gets deleted. 218 00:11:57,516 --> 00:11:57,846 Right. 219 00:11:58,116 --> 00:12:02,376 You could also set it to be a year, you could set it to be seven years, 220 00:12:03,036 --> 00:12:03,516 whatever. 221 00:12:03,516 --> 00:12:07,716 You can set different retention policies for, uh, email, for 222 00:12:07,721 --> 00:12:09,786 SharePoint, for OneDrive. 223 00:12:10,866 --> 00:12:13,836 You can set all these different, uh, policies. 224 00:12:14,016 --> 00:12:16,266 You can also set a single policy. 225 00:12:16,746 --> 00:12:20,106 Everything in Microsoft 365 is kept for. 226 00:12:20,571 --> 00:12:23,481 End days and no longer, right. 227 00:12:24,021 --> 00:12:27,951 Um, you can set it at a group level, you can set it at an individual level. 228 00:12:28,881 --> 00:12:37,671 And the, the reason why, uh, and it has an optional, um, uh, and what, 229 00:12:37,881 --> 00:12:42,591 what I'm gonna call, and I really mean it feature, um, which is a 230 00:12:42,591 --> 00:12:46,791 checkbox that says once you set it. 231 00:12:47,706 --> 00:12:49,896 Uh, you can't change your mind. 232 00:12:50,316 --> 00:12:55,116 So once you say Everything in this environment should be 233 00:12:55,116 --> 00:12:58,656 kept for a year, you can't. 234 00:12:58,656 --> 00:13:02,526 Then 60 days later, change your mind. 235 00:13:02,526 --> 00:13:03,906 Say, I, I, I'm sorry. 236 00:13:03,911 --> 00:13:06,066 I meant, I meant something Way less than a year. 237 00:13:06,246 --> 00:13:06,996 Sorry. 238 00:13:07,176 --> 00:13:08,796 You've turned it on for a year. 239 00:13:08,886 --> 00:13:09,306 Right? 240 00:13:09,636 --> 00:13:14,676 Prasanna Malaiyandi: that means any data created stays for that year. 241 00:13:15,666 --> 00:13:16,116 W. Curtis Preston: Right. 242 00:13:16,331 --> 00:13:19,356 Prasanna Malaiyandi: if I created new data after changing into 60 days, 243 00:13:19,596 --> 00:13:21,276 new data would stay for 60 days. 244 00:13:21,276 --> 00:13:22,656 Old data would stay for one year. 245 00:13:23,871 --> 00:13:25,071 W. Curtis Preston: right, right. 246 00:13:25,371 --> 00:13:33,051 And so what can happen if you use this policy is so, and the, the reason 247 00:13:33,051 --> 00:13:38,691 why I say this is those that are proponents of using retention policies. 248 00:13:39,261 --> 00:13:43,371 Instead of backup, they basically say, look, Microsoft is really resilient. 249 00:13:43,671 --> 00:13:46,401 They've got delayed copies and all this kind of stuff in there. 250 00:13:46,401 --> 00:13:50,841 And so, so really like, like Microsoft will protect the 251 00:13:50,841 --> 00:13:52,911 Microsoft environment, right? 252 00:13:53,511 --> 00:13:57,471 And that if they have to recover the Microsoft environment, you will get 253 00:13:57,471 --> 00:14:00,051 recovered as a consequence of that. 254 00:14:00,471 --> 00:14:04,671 So you don't, these are the proponents of, of, of this, this 255 00:14:04,671 --> 00:14:06,441 is not me, this is, you know. 256 00:14:06,891 --> 00:14:07,461 Prasanna Malaiyandi: Other folks. 257 00:14:08,421 --> 00:14:11,601 W. Curtis Preston: Um, they'll say, you don't, you don't have to worry about that. 258 00:14:11,601 --> 00:14:15,291 What you need to worry about is a ransomware attack or a 259 00:14:15,291 --> 00:14:19,221 massive accidental deletion, like what happened at KPMG, right? 260 00:14:19,521 --> 00:14:19,581 Prasanna Malaiyandi: Yeah. 261 00:14:20,241 --> 00:14:23,121 W. Curtis Preston: And so you can say, um. 262 00:14:24,021 --> 00:14:29,151 Uh, everything gets kept for X amount of days, and you can check the box that says, 263 00:14:29,541 --> 00:14:32,511 um, you know, and I can't change my mind. 264 00:14:32,901 --> 00:14:37,941 And then after, you know, 30, 60, 90 days when you find out what that does to 265 00:14:37,941 --> 00:14:44,091 your storage and you're like, holy cow, I didn't realize this was going to do this 266 00:14:44,091 --> 00:14:46,941 to my storage, and subsequently my bill. 267 00:14:47,136 --> 00:14:47,346 Prasanna Malaiyandi: Yeah. 268 00:14:47,976 --> 00:14:49,986 W. Curtis Preston: You can't change your mind. 269 00:14:50,286 --> 00:14:54,066 I mean, you can change your mind, but you can't change your mind for that period. 270 00:14:54,996 --> 00:14:56,586 It's not retroactive, right? 271 00:14:56,886 --> 00:15:01,026 You told it, you know that you wanted to keep it and you wanted to do the, you 272 00:15:01,026 --> 00:15:03,366 know, the uh, the compliance feature. 273 00:15:03,661 --> 00:15:04,891 Prasanna Malaiyandi: Since you just mentioned compliance, 274 00:15:04,891 --> 00:15:07,081 so retention though, right? 275 00:15:07,081 --> 00:15:10,291 It's typically associated with a compliance policy. 276 00:15:11,206 --> 00:15:11,566 W. Curtis Preston: Right. 277 00:15:11,716 --> 00:15:15,886 Prasanna Malaiyandi: And even if the user goes and deletes that email before 278 00:15:15,886 --> 00:15:19,696 the retention period is up, because it's sort of intended for compliance, 279 00:15:19,701 --> 00:15:24,556 that email is still kept around until the retention policy expires. 280 00:15:25,486 --> 00:15:25,906 W. Curtis Preston: Right. 281 00:15:25,906 --> 00:15:26,116 Yeah. 282 00:15:26,116 --> 00:15:31,786 When, when, when I delete an email, all it does is set the don't show it to Curtis 283 00:15:31,821 --> 00:15:32,111 Prasanna Malaiyandi: Yeah. 284 00:15:34,006 --> 00:15:34,816 W. Curtis Preston: It's still there. 285 00:15:34,966 --> 00:15:35,386 Right. 286 00:15:35,926 --> 00:15:39,436 Um, the, and, and the other thing is that. 287 00:15:40,066 --> 00:15:44,086 It's designed, you, you said it's designed for compliance. 288 00:15:44,446 --> 00:15:48,946 It's designed, it's the complete opposite of backup. 289 00:15:49,546 --> 00:15:49,786 Right. 290 00:15:49,791 --> 00:15:53,296 So you know how we talk a lot about backup versus archive. 291 00:15:54,106 --> 00:16:00,196 This is much more about archive and retrieval and e-discovery than it is about 292 00:16:00,466 --> 00:16:03,256 recovering Curtis's email box because 293 00:16:03,336 --> 00:16:04,621 Prasanna Malaiyandi: To no point in time. 294 00:16:04,741 --> 00:16:05,761 At no point in time. 295 00:16:06,586 --> 00:16:10,876 W. Curtis Preston: Yeah, at a point in time, what it can do is you can 296 00:16:10,876 --> 00:16:13,636 go then do an e-discovery case. 297 00:16:13,936 --> 00:16:15,586 First off, you need different permissions. 298 00:16:15,591 --> 00:16:19,546 It's different than like the default system admin, uh, permissions. 299 00:16:19,816 --> 00:16:22,696 You need separate permiss permissions to do this, and then you can 300 00:16:22,696 --> 00:16:27,436 go in and say, please extract all of the email that Curtis. 301 00:16:28,096 --> 00:16:31,276 Has ever received or received in this time period. 302 00:16:31,306 --> 00:16:35,596 And then they can throw that in your inbox all in one big pile, not in the folders 303 00:16:35,596 --> 00:16:36,946 or whatever, that you had it before. 304 00:16:36,946 --> 00:16:40,576 And by the way, not just email, but the same is true in SharePoint or whatever. 305 00:16:41,056 --> 00:16:43,846 Um, it's just a big pile of stuff. 306 00:16:43,906 --> 00:16:46,156 And then they put it back, and then you gotta go figure out 307 00:16:46,846 --> 00:16:48,436 what what you don't need, right? 308 00:16:48,496 --> 00:16:52,786 Prasanna Malaiyandi: and usually you use retention policies because keeping data 309 00:16:52,786 --> 00:16:55,756 around is actually sometimes a bad idea, 310 00:16:56,956 --> 00:16:57,826 W. Curtis Preston: Right, right. 311 00:16:57,826 --> 00:17:00,706 This is a, it's a legal, it's a legal issue, right? 312 00:17:01,036 --> 00:17:03,916 And so you say, look, we're not gonna keep data longer than a year. 313 00:17:04,411 --> 00:17:05,641 Um, period. 314 00:17:05,641 --> 00:17:08,671 You know, I know that when I worked at Druva, they had implemented a data 315 00:17:08,671 --> 00:17:11,221 retention policy on Slack, for example. 316 00:17:11,251 --> 00:17:11,581 Right. 317 00:17:12,091 --> 00:17:15,841 Um, you know, they only would allow Slack messages for I think it was like 90 days 318 00:17:15,886 --> 00:17:16,216 Prasanna Malaiyandi: Yeah. 319 00:17:16,811 --> 00:17:19,121 W. Curtis Preston: So, so a couple of things about retention policies. 320 00:17:19,121 --> 00:17:22,991 One is, it, it's not good at restore it, it any more, any more 321 00:17:22,991 --> 00:17:27,821 than a backup tool is good at, at e-Discovery, this is an e-discovery 322 00:17:27,821 --> 00:17:29,381 tool that's not good at backup. 323 00:17:29,381 --> 00:17:30,401 It's not good at Restore. 324 00:17:31,001 --> 00:17:31,601 And so 325 00:17:31,871 --> 00:17:34,246 if you got a large ransomware attack. 326 00:17:34,886 --> 00:17:36,416 It wouldn't be good at that, right? 327 00:17:36,836 --> 00:17:41,726 The other thing is that it can result in significant increases in your cost, right? 328 00:17:41,726 --> 00:17:45,506 And your storage, as opposed to just using a backup tool, which would 329 00:17:45,511 --> 00:17:48,506 also have an increase in cost, but a different increase in cost, right? 330 00:17:48,506 --> 00:17:50,576 And more, and a more predictable increase in cost. 331 00:17:51,071 --> 00:17:58,136 Um, and then, and to the point of this story, it can 332 00:17:58,136 --> 00:17:59,276 sometimes really screw you up. 333 00:17:59,936 --> 00:18:00,146 Prasanna Malaiyandi: yeah. 334 00:18:00,146 --> 00:18:02,846 If you don't understand and aren't careful, 335 00:18:03,701 --> 00:18:07,961 W. Curtis Preston: Yeah, so as I understand it, so the way that they 336 00:18:07,961 --> 00:18:13,091 would've done this, and this, by the way, this is inference not information. 337 00:18:14,441 --> 00:18:22,541 When you've got 145,000 people and you have, um, one person whose 338 00:18:22,541 --> 00:18:27,761 private chats you wanna delete, and you've got a retention policy that 339 00:18:27,761 --> 00:18:30,191 says for 145,000 people, we keep. 340 00:18:30,881 --> 00:18:35,411 You know, private chats for six months, whatever, whatever the number is, right? 341 00:18:35,411 --> 00:18:43,451 90 days, you can't, you can't delete those private chats as long as that person is in 342 00:18:43,871 --> 00:18:46,001 the, um, in that policy. 343 00:18:46,571 --> 00:18:51,581 So you have to create a different policy that says private chats 344 00:18:51,581 --> 00:18:56,951 get kept for one day, and then you move that user into that policy. 345 00:18:56,981 --> 00:18:57,281 Prasanna Malaiyandi: Yep. 346 00:18:59,696 --> 00:19:01,976 W. Curtis Preston: Apparently they just, they did the wrong 347 00:19:02,261 --> 00:19:03,671 Prasanna Malaiyandi: They just edited the policy. 348 00:19:04,616 --> 00:19:05,516 W. Curtis Preston: they create, yeah. 349 00:19:05,516 --> 00:19:11,066 They edited the policy, uh, and then poof instantly. 350 00:19:11,576 --> 00:19:14,486 And again, they didn't have the, the flag. 351 00:19:14,576 --> 00:19:16,286 See if they had, had the flag turned on. 352 00:19:16,556 --> 00:19:16,676 And 353 00:19:16,796 --> 00:19:18,146 Prasanna Malaiyandi: Their old data would've been fine. 354 00:19:18,836 --> 00:19:20,396 W. Curtis Preston: Yeah, the old data would've been fine. 355 00:19:20,846 --> 00:19:25,496 Um, they, they wouldn't have been able to, to, to mess it up like this. 356 00:19:26,006 --> 00:19:29,066 So one message could be, if you're gonna use retention policies, 357 00:19:29,066 --> 00:19:30,176 you better turn on that flag. 358 00:19:30,206 --> 00:19:32,756 'cause they all, they're all they, they are all you have. 359 00:19:32,936 --> 00:19:35,876 Prasanna Malaiyandi: Well, it wouldn't save you though from 360 00:19:35,936 --> 00:19:38,756 new messages created, so you 361 00:19:38,936 --> 00:19:41,246 W. Curtis Preston: No, but at least you wouldn't have deleted six months. 362 00:19:41,281 --> 00:19:41,726 Prasanna Malaiyandi: No, no, no. 363 00:19:41,726 --> 00:19:42,416 But it would've been 364 00:19:42,476 --> 00:19:43,856 W. Curtis Preston: this out in about five minutes, you 365 00:19:44,006 --> 00:19:49,766 Prasanna Malaiyandi: But would you though, because now anything new that 366 00:19:49,766 --> 00:19:53,456 you type would be following that new policy and maybe you don't realize it. 367 00:19:54,626 --> 00:19:56,426 W. Curtis Preston: Yeah, I just, I just think it would be, it would 368 00:19:56,431 --> 00:19:59,906 be less of a tragedy than Right. 369 00:20:00,866 --> 00:20:05,096 Um, and, and I, I do think it's important to say that had they, 370 00:20:05,351 --> 00:20:08,901 there are no APIs for restoring. 371 00:20:09,761 --> 00:20:12,011 Um, teams messages. 372 00:20:12,581 --> 00:20:16,541 There are APIs and there are ways to get these messages. 373 00:20:16,541 --> 00:20:20,351 They are, and some of them are frankly, very klugy. 374 00:20:21,071 --> 00:20:24,581 Um, I, I remember, I remember participating in some of these 375 00:20:24,586 --> 00:20:27,521 conversations, you know, when I was at Druva, getting some of this data 376 00:20:27,526 --> 00:20:32,261 is very klugy because it wasn't really designed to be gotten right. 377 00:20:34,616 --> 00:20:39,656 If you had done, if they had done that, they wouldn't have been able 378 00:20:39,656 --> 00:20:41,756 to restore the team's messages, but 379 00:20:41,801 --> 00:20:42,701 Prasanna Malaiyandi: would've had it at least. 380 00:20:42,866 --> 00:20:44,966 W. Curtis Preston: they would've at least had it. 381 00:20:45,266 --> 00:20:48,776 And if there was anything important in there, which there shouldn't 382 00:20:48,776 --> 00:20:55,346 be, there shouldn't be important stuff and private messages. 383 00:20:56,456 --> 00:21:01,556 Um, but remember, we live in a world where people use their recycle bin for storage. 384 00:21:02,426 --> 00:21:02,846 Right. 385 00:21:03,056 --> 00:21:04,286 Um, right. 386 00:21:04,286 --> 00:21:04,856 You've seen that, 387 00:21:05,046 --> 00:21:05,266 Prasanna Malaiyandi: Yep. 388 00:21:07,496 --> 00:21:10,466 W. Curtis Preston: Um, you are like, Hey, your hard drive is filled, and you, you 389 00:21:10,466 --> 00:21:12,536 click the recycle bin like, whatcha doing? 390 00:21:12,746 --> 00:21:14,636 You just deleted my storage area. 391 00:21:18,131 --> 00:21:21,731 Yeah, that actually was the last thing that happened to me 392 00:21:21,731 --> 00:21:25,181 at the bank was, was deleting. 393 00:21:25,391 --> 00:21:27,461 I rebooted a server 394 00:21:28,421 --> 00:21:28,751 Prasanna Malaiyandi: It was 395 00:21:28,871 --> 00:21:33,371 W. Curtis Preston: well, somebody rebooted a server and it was, it was hp 396 00:21:33,371 --> 00:21:39,431 where HP that slash TMP was in ram and we found out a whole bunch of developers 397 00:21:39,431 --> 00:21:40,931 had stored their code tree there. 398 00:21:42,866 --> 00:21:44,666 And they were like, this is really important. 399 00:21:44,666 --> 00:21:46,316 I'm like, then you shouldn't have put it in temp. 400 00:21:46,316 --> 00:21:48,416 And they were very angry because we didn't back up temp 401 00:21:49,741 --> 00:21:50,161 Prasanna Malaiyandi: Who would? 402 00:21:50,191 --> 00:21:50,681 It's Tim. 403 00:21:50,696 --> 00:21:56,366 W. Curtis Preston: temp and, uh, we lost months of development work. 404 00:21:57,056 --> 00:21:57,116 Um. 405 00:21:58,766 --> 00:22:00,356 So we live in that kind of world, right? 406 00:22:00,356 --> 00:22:04,736 And so, um, people do sometimes put important stuff in there and 407 00:22:04,736 --> 00:22:07,886 anything that was important there were in messages, which shouldn't 408 00:22:07,886 --> 00:22:13,166 have been, but anything that was there would've been instantly, um, deleted. 409 00:22:13,616 --> 00:22:17,006 Sort of like, uh, opening the door, uh, when you're out to space, 410 00:22:19,511 --> 00:22:20,111 Prasanna Malaiyandi: Don't do it. 411 00:22:21,611 --> 00:22:22,201 W. Curtis Preston: don't do it. 412 00:22:22,601 --> 00:22:24,251 Prasanna Malaiyandi: So, so let's go back to this, right? 413 00:22:24,251 --> 00:22:27,761 So they lost a bunch of messages because someone accidentally 414 00:22:27,766 --> 00:22:28,901 set the retention policy. 415 00:22:29,171 --> 00:22:31,241 What should they have done? 416 00:22:32,801 --> 00:22:35,501 What could they have done to make this less painful? 417 00:22:36,716 --> 00:22:38,306 W. Curtis Preston: Well, I, I'd say a couple of things. 418 00:22:38,306 --> 00:22:43,316 One, the first and most obvious to me was if they had a backup, then this 419 00:22:43,316 --> 00:22:45,296 would've been less painful, right? 420 00:22:45,391 --> 00:22:50,246 They would've been able to at least retrieve, you know, important data. 421 00:22:50,726 --> 00:22:50,756 I. 422 00:22:51,086 --> 00:22:55,136 And by the way, not all, not all products at Backup 365 are able to 423 00:22:55,136 --> 00:22:57,476 get anything out of teams, right. 424 00:22:57,536 --> 00:22:58,466 Teams messages. 425 00:22:59,246 --> 00:23:04,496 Uh, some have to different degree, different levels of success. 426 00:23:04,501 --> 00:23:04,706 Right. 427 00:23:04,706 --> 00:23:08,786 But, but they would've had the possibility of getting that data back. 428 00:23:09,326 --> 00:23:14,126 And number two is, it is a little surprising that an admin would 429 00:23:14,126 --> 00:23:17,366 do something of that level. 430 00:23:18,031 --> 00:23:18,151 I. 431 00:23:18,761 --> 00:23:19,811 With a mouse. 432 00:23:20,081 --> 00:23:20,471 Right, 433 00:23:21,776 --> 00:23:24,746 Prasanna Malaiyandi: Without any controls or any checks or anything else like 434 00:23:24,881 --> 00:23:26,231 W. Curtis Preston: yeah, yeah, 435 00:23:26,341 --> 00:23:28,016 Prasanna Malaiyandi: at least approve or look over, Hey, 436 00:23:28,016 --> 00:23:29,216 are you doing the right thing? 437 00:23:30,371 --> 00:23:30,611 W. Curtis Preston: yeah. 438 00:23:30,611 --> 00:23:36,101 You would think that something of that level, you know, I, I guess he wasn't 439 00:23:36,101 --> 00:23:42,701 thinking or she wasn't thinking that, um, they were just thinking one person. 440 00:23:42,761 --> 00:23:43,631 It's just one guy. 441 00:23:43,931 --> 00:23:44,891 I'm just doing one guy. 442 00:23:44,936 --> 00:23:47,426 Prasanna Malaiyandi: But that's where a process becomes so critical, right. 443 00:23:47,426 --> 00:23:48,656 And documenting process and. 444 00:23:50,306 --> 00:23:51,416 W. Curtis Preston: yeah, yeah. 445 00:23:51,596 --> 00:23:56,306 So they could have, they also could, had they enabled the, the 446 00:23:56,306 --> 00:23:59,006 retention lock, that's what it's called, the retention lock feature. 447 00:23:59,786 --> 00:24:02,786 They would've at least kept the data from before. 448 00:24:03,476 --> 00:24:07,976 Um, and they would've, they would've minimized the pain if they turned 449 00:24:07,976 --> 00:24:09,206 on the retention lot feature. 450 00:24:09,476 --> 00:24:12,356 But I'm not a big fan of the retention lot feature because. 451 00:24:13,376 --> 00:24:17,066 Its potential significant increase in, uh, in storage costs. 452 00:24:17,186 --> 00:24:20,666 Prasanna Malaiyandi: and especially, it's so hard to predict how much 453 00:24:20,666 --> 00:24:24,986 space you have or would be consuming before you enable that feature. 454 00:24:24,991 --> 00:24:29,636 Like any sort of capacity planning or sizing, calculators, I've seen even for 455 00:24:29,636 --> 00:24:33,116 general storage, they're not accurate because your workload is going to 456 00:24:33,146 --> 00:24:36,506 change and it's going to depend on your environment and how people use the tools. 457 00:24:36,506 --> 00:24:38,876 And so it's just a best guess. 458 00:24:38,876 --> 00:24:42,141 And until you actually turn it on, start using it, you're never gonna know. 459 00:24:43,436 --> 00:24:47,906 W. Curtis Preston: Yeah, I would think that if, if you're gonna use the retention 460 00:24:47,906 --> 00:24:50,546 policies instead of backup, right? 461 00:24:50,636 --> 00:24:55,406 Which you shouldn't do, but if you did, should turn it on for, let's 462 00:24:55,406 --> 00:25:00,026 say three months and see what it does to your storage and then, and 463 00:25:00,026 --> 00:25:02,996 then make a decision at that point as to whether or not you wanna. 464 00:25:03,416 --> 00:25:04,676 Essentially make this permanent. 465 00:25:05,576 --> 00:25:08,576 Uh, and then when you see what it does to your storage, then maybe have 466 00:25:08,576 --> 00:25:12,386 a conversation with a backup vendor and say, Hey, can you do this with 467 00:25:12,386 --> 00:25:13,976 less of an impact to my environment? 468 00:25:14,756 --> 00:25:15,086 Right. 469 00:25:15,806 --> 00:25:23,156 Um, now some people, you know, you know, so I read, uh, with, with great delight. 470 00:25:24,056 --> 00:25:27,506 I read the comments in Reddit, there's a Reddit thread 471 00:25:27,506 --> 00:25:29,366 about this, and there's also. 472 00:25:29,921 --> 00:25:33,401 A comment thread from the register article. 473 00:25:33,401 --> 00:25:35,501 I, it's one thing I love about the register is that they have 474 00:25:35,501 --> 00:25:37,236 comments and boy do people get in. 475 00:25:38,261 --> 00:25:38,441 What's 476 00:25:38,471 --> 00:25:40,121 Prasanna Malaiyandi: We'll, the links in the show notes. 477 00:25:40,241 --> 00:25:40,421 W. Curtis Preston: Yeah. 478 00:25:40,631 --> 00:25:41,231 Thanks to those. 479 00:25:41,236 --> 00:25:41,561 Yeah. 480 00:25:42,011 --> 00:25:46,571 Um, you know, and you know, of course you got the standard stupid cloud, you know, 481 00:25:46,571 --> 00:25:50,201 it's where you want to put, you know, I'm like, dude, this could have been exchange, 482 00:25:51,311 --> 00:25:51,821 right? 483 00:25:51,971 --> 00:25:53,801 Uh, this could have been an exchange environment. 484 00:25:53,831 --> 00:25:54,251 Right. 485 00:25:55,391 --> 00:25:55,841 Um. 486 00:25:56,741 --> 00:25:59,621 Then the other, of course, is, well, why didn't they go, why 487 00:25:59,621 --> 00:26:00,791 didn't they go to their backup? 488 00:26:01,241 --> 00:26:05,801 Like, people just completely ignorant that, and, and I, 489 00:26:06,071 --> 00:26:07,421 that that's the proper word. 490 00:26:07,421 --> 00:26:09,461 People like, they're like, oh, that's pejorative. 491 00:26:10,181 --> 00:26:11,081 It's the proper word. 492 00:26:11,081 --> 00:26:16,841 They don't know that Microsoft 365 doesn't have backup. 493 00:26:17,021 --> 00:26:19,451 If you are not providing it, it doesn't have it. 494 00:26:20,021 --> 00:26:23,381 Prasanna Malaiyandi: Given how big KPMG is and what sort of 495 00:26:23,501 --> 00:26:27,821 things that they provide to their clients, that's a little shocking. 496 00:26:27,821 --> 00:26:30,671 If they didn't know that there's no backups. 497 00:26:31,481 --> 00:26:31,991 I'm sorry. 498 00:26:31,991 --> 00:26:34,301 That's just bonkers. 499 00:26:35,721 --> 00:26:38,726 W. Curtis Preston: It is bonkers, but it's a bonkers that I run into all the time. 500 00:26:39,296 --> 00:26:39,716 Right. 501 00:26:40,076 --> 00:26:42,686 Um, yeah. 502 00:26:43,931 --> 00:26:46,181 Prasanna Malaiyandi: so I know that we're looking at this as 503 00:26:46,181 --> 00:26:47,861 people lost a bunch of data. 504 00:26:48,451 --> 00:26:48,871 W. Curtis Preston: Mm-hmm. 505 00:26:48,896 --> 00:26:50,546 Prasanna Malaiyandi: And people lost their chats. 506 00:26:50,546 --> 00:26:50,786 Right? 507 00:26:50,786 --> 00:26:53,726 It was probably a lot of sensitive information or 508 00:26:53,966 --> 00:26:55,406 important information was lost. 509 00:26:56,006 --> 00:27:00,776 I was just going in my head about what, that must be amazing because 510 00:27:00,781 --> 00:27:02,936 it's like you hit a reset, you don't have to worry about deleting 511 00:27:02,936 --> 00:27:05,336 conversations or anything else, right? 512 00:27:05,666 --> 00:27:06,806 It's like clean slate. 513 00:27:06,806 --> 00:27:08,336 It's like you start a new job somewhere. 514 00:27:08,336 --> 00:27:12,386 It's like no previous chat messages, no baggage, no nothing 515 00:27:12,386 --> 00:27:13,286 that you have to worry about. 516 00:27:15,061 --> 00:27:15,351 W. Curtis Preston: Yeah. 517 00:27:16,136 --> 00:27:18,566 Well, the, the other, the other thing, when I think about this. 518 00:27:19,301 --> 00:27:22,361 Uh, again, when I talk about this other person, you know, they're like, 519 00:27:22,361 --> 00:27:24,611 well, it was just private messages. 520 00:27:24,851 --> 00:27:27,251 You shouldn't have been putting anything of value in private 521 00:27:27,281 --> 00:27:28,031 Prasanna Malaiyandi: do that all the 522 00:27:28,246 --> 00:27:30,611 W. Curtis Preston: That is that people do it all the time. 523 00:27:30,611 --> 00:27:30,941 Right. 524 00:27:31,541 --> 00:27:32,021 But they're right. 525 00:27:32,021 --> 00:27:32,591 They're right. 526 00:27:32,711 --> 00:27:33,371 You shouldn't do. 527 00:27:33,431 --> 00:27:33,821 Right. 528 00:27:34,931 --> 00:27:39,671 But this could have just as easily been email, 529 00:27:41,381 --> 00:27:42,116 Prasanna Malaiyandi: Or SharePoint. 530 00:27:43,586 --> 00:27:44,876 W. Curtis Preston: Or SharePoint, right? 531 00:27:44,906 --> 00:27:48,626 So retention policies are global. 532 00:27:48,806 --> 00:27:52,736 If you want them to be right, you can make them as granular as you want. 533 00:27:52,976 --> 00:27:58,016 Retention policy for one person, which is what they were trying to do, they could 534 00:27:58,016 --> 00:28:01,226 have just as easily deleted all email 535 00:28:01,271 --> 00:28:01,561 Prasanna Malaiyandi: yeah. 536 00:28:02,331 --> 00:28:03,351 W. Curtis Preston: in the environment. 537 00:28:04,811 --> 00:28:08,651 They would've had no backup, they would've had no recourse. 538 00:28:08,861 --> 00:28:13,301 'cause the, the whole point of retention policies, by the way, I mean this is maybe 539 00:28:13,301 --> 00:28:14,591 something I should have mentioned before. 540 00:28:15,281 --> 00:28:20,951 The point of them is that if you say don't keep it longer than 541 00:28:20,951 --> 00:28:23,291 X, it gets rid of everything. 542 00:28:24,416 --> 00:28:29,906 It, you know, it, it, it keeps it longer than, you know, if you said it's to 90 543 00:28:29,906 --> 00:28:32,366 days, it, it deals with the, recycle bin. 544 00:28:32,576 --> 00:28:32,936 Right. 545 00:28:33,446 --> 00:28:38,071 But wherever that entity is, that record, that email, 546 00:28:38,081 --> 00:28:39,701 Prasanna Malaiyandi: Once it's 90 days, it's boom. 547 00:28:39,911 --> 00:28:40,301 Gone. 548 00:28:40,491 --> 00:28:41,996 W. Curtis Preston: it, boom, it's gone. 549 00:28:42,356 --> 00:28:47,156 And in this case, they set 90 to one or zero. 550 00:28:48,206 --> 00:28:51,446 And that basically that means that there was no recycle bin 551 00:28:51,446 --> 00:28:53,846 for them to go get this out of. 552 00:28:54,206 --> 00:28:58,436 And that means if they did the same thing with email, they would've wiped out 553 00:28:58,436 --> 00:29:01,616 the entire organization's entire email 554 00:29:01,616 --> 00:29:02,336 infrastructure 555 00:29:02,911 --> 00:29:05,116 Prasanna Malaiyandi: Or if they did that with One Drive, then 556 00:29:05,136 --> 00:29:06,451 all the documents are gone. 557 00:29:06,481 --> 00:29:06,871 Right. 558 00:29:07,081 --> 00:29:10,871 So here's my question though, is assuming that they wanted to, because. 559 00:29:11,441 --> 00:29:15,131 Given that they wanted to set this user's retention policy to zero, that pretty 560 00:29:15,131 --> 00:29:16,481 much means they want all the data gone. 561 00:29:17,786 --> 00:29:18,176 W. Curtis Preston: Right. 562 00:29:18,701 --> 00:29:20,771 Prasanna Malaiyandi: Why didn't they just delete the user? 563 00:29:23,516 --> 00:29:26,396 W. Curtis Preston: Uh, because it would, the data would've stayed. 564 00:29:28,196 --> 00:29:29,416 Prasanna Malaiyandi: Oh, okay. 565 00:29:30,536 --> 00:29:30,776 W. Curtis Preston: Yeah. 566 00:29:30,776 --> 00:29:32,846 Again, that's the whole point of retention policies. 567 00:29:33,926 --> 00:29:34,316 Right. 568 00:29:34,766 --> 00:29:37,526 Um, and, and I don't know, you know, I mean, we can. 569 00:29:37,841 --> 00:29:43,001 We can theorize as to what did this user say in their private messages 570 00:29:43,001 --> 00:29:45,221 that they've really wanted gone. 571 00:29:46,181 --> 00:29:52,241 Um, we can theorize, by the way, there are theories I, I, I should just mention 572 00:29:52,241 --> 00:29:55,361 them as long as we're talking about When I look, when you look at the thread, 573 00:29:56,561 --> 00:30:04,181 there, there were, uh, pending legal matters where these private messages. 574 00:30:04,571 --> 00:30:12,281 Perhaps could have been helpful, but now they're not available and this story would 575 00:30:12,281 --> 00:30:18,491 at least be a legally defensible reason why, why it deleted our admin screwed up. 576 00:30:18,731 --> 00:30:25,061 This wasn't spoilage, this wasn't purposeful deletion because of of a 577 00:30:25,061 --> 00:30:30,611 lawsuit, but it also violates if they had a lawsuit that included this data. 578 00:30:31,211 --> 00:30:37,571 It, it could potentially create, uh, an adverse inference, um, thing. 579 00:30:37,571 --> 00:30:41,406 And I'll just explain that for those that don't, basically if you're being 580 00:30:41,411 --> 00:30:47,286 sued or being prosecuted for something, if the judge believes that you have 581 00:30:47,286 --> 00:30:53,976 either destroyed evidence or have behaved poorly the, basically the judge 582 00:30:53,976 --> 00:30:58,566 can infer from that behavior something adverse to your case, and they could 583 00:30:58,566 --> 00:31:00,606 literally, like in the case of a jury. 584 00:31:00,891 --> 00:31:04,401 They can literally turn to the jury and say whatever the plaintiff said 585 00:31:04,941 --> 00:31:08,991 was in those private messages, just go ahead and assume it was there 586 00:31:09,531 --> 00:31:14,001 because why the hell else would they delete the private messages? 587 00:31:14,181 --> 00:31:14,601 Right? 588 00:31:14,901 --> 00:31:17,151 That's what's called an adverse inference instruction. 589 00:31:17,571 --> 00:31:21,201 Um, and or if you know, if the judge is by themselves, they can just do it, 590 00:31:21,471 --> 00:31:24,321 Prasanna Malaiyandi: but, and I do wonder though if given the fact that 591 00:31:24,321 --> 00:31:30,081 they weren't doing backups of this data, I wonder if that does qualify for that. 592 00:31:31,041 --> 00:31:31,341 Right. 593 00:31:31,341 --> 00:31:36,471 Because yeah, you can blame that the admin was, did something by mistake, 594 00:31:36,651 --> 00:31:41,811 but there's no reason you shouldn't have backups of business data, you know? 595 00:31:44,061 --> 00:31:45,536 W. Curtis Preston: Well, you know, I agree with you there. 596 00:31:49,986 --> 00:31:54,246 They possibly could say, well, even if we had backups, we wouldn't have had the 597 00:31:54,246 --> 00:31:55,896 data or whatever, because it's teams, 598 00:31:56,331 --> 00:31:59,721 Prasanna Malaiyandi: But you have the data, you could extract it as on, you'd 599 00:31:59,726 --> 00:32:02,661 maybe not restore it directly back into teams, but at least you have the data. 600 00:32:04,206 --> 00:32:04,656 W. Curtis Preston: Yeah. 601 00:32:04,711 --> 00:32:12,606 I, I think that, well, any adverse inference that could be inferred 602 00:32:12,606 --> 00:32:18,186 from their behavior is in the sole discretion of, of a judge. 603 00:32:18,651 --> 00:32:19,041 Right. 604 00:32:19,041 --> 00:32:24,231 And so the judge d different judges are going to have, uh, different levels 605 00:32:24,231 --> 00:32:29,931 of like, you know, do they, do they believe that people are inherently good? 606 00:32:30,891 --> 00:32:32,151 Right, right. 607 00:32:32,181 --> 00:32:37,761 Uh, you know, they're, who knows what it, uh, this was four years ago. 608 00:32:37,761 --> 00:32:40,791 We could probably find out, but, uh, I didn't care that much 609 00:32:40,791 --> 00:32:43,311 about the part of it, but I just wanted to say that this was. 610 00:32:43,971 --> 00:32:49,461 Part people were specifically pointed to specific cases that, uh, this is in 611 00:32:49,461 --> 00:32:52,941 the, the register thread, by the way, for anyone who wants to look it up. 612 00:32:53,841 --> 00:32:58,731 Um, this certainly is a nice way to get rid of a bunch of data with a nice story. 613 00:32:58,731 --> 00:33:02,181 That doesn't sound like you're trying to do it purposefully. 614 00:33:02,361 --> 00:33:05,451 I'm not saying that that's what happened, but I'm saying some people 615 00:33:05,721 --> 00:33:06,921 so, so here's the thing. 616 00:33:07,101 --> 00:33:10,641 In summary, Microsoft 365 isnt magic. 617 00:33:10,731 --> 00:33:11,991 The cloud isn't magic. 618 00:33:12,891 --> 00:33:16,461 You, you need to back up the cloud somehow, right? 619 00:33:16,461 --> 00:33:20,871 Just like, it's not like people thought that, especially certain 620 00:33:20,871 --> 00:33:24,171 people thought that I was saying this just because I work for dva, right? 621 00:33:24,231 --> 00:33:25,611 Well, I don't work for Duv anymore. 622 00:33:26,211 --> 00:33:29,391 Uh, the, the, it's not magic, right? 623 00:33:29,901 --> 00:33:32,901 You know, it, it needs some kind of backup. 624 00:33:33,051 --> 00:33:35,391 I don't, I don't, it doesn't have to be a third party. 625 00:33:35,541 --> 00:33:37,431 I would prefer it be a third party. 626 00:33:38,001 --> 00:33:38,481 Right. 627 00:33:38,571 --> 00:33:44,871 So you look at like, so Microsoft is starting to talk about snapshots 628 00:33:45,861 --> 00:33:47,091 and some sort of recovery. 629 00:33:47,091 --> 00:33:54,051 I don't yet know how that will all play out, but in general, and, and if it meets. 630 00:33:54,846 --> 00:33:54,906 Prasanna Malaiyandi: The 631 00:33:54,906 --> 00:33:56,946 W. Curtis Preston: The usual, like 3, 2, 1 requirement. 632 00:33:56,976 --> 00:34:00,306 'cause again, going back to the 3, 2, 1 rule, having three copies of your data, 633 00:34:00,306 --> 00:34:04,506 two of which on, you know, different media with different risk profiles, one 634 00:34:04,506 --> 00:34:05,946 of which being stored somewhere else. 635 00:34:06,126 --> 00:34:09,306 The thing with 365 and a lot of SaaS providers is that they don't 636 00:34:09,306 --> 00:34:11,646 do the two or the one, right? 637 00:34:11,706 --> 00:34:12,576 It don't do any of this. 638 00:34:12,576 --> 00:34:14,676 They don't have a separate copy of your data. 639 00:34:15,036 --> 00:34:16,476 That that's, that's basic. 640 00:34:17,976 --> 00:34:19,266 It's not magic. 641 00:34:19,566 --> 00:34:21,066 The cloud doesn't solve all new problems. 642 00:34:21,066 --> 00:34:24,456 In fact, it creates new ones and I'm pro cloud. 643 00:34:26,136 --> 00:34:26,526 Right. 644 00:34:27,231 --> 00:34:29,301 Prasanna Malaiyandi: How are you feeling Curtis, about this? 645 00:34:30,306 --> 00:34:30,936 W. Curtis Preston: I know. 646 00:34:30,996 --> 00:34:31,986 I was in a pretty good mood. 647 00:34:31,986 --> 00:34:32,586 The beginning of this. 648 00:34:36,966 --> 00:34:37,386 You to. 649 00:34:40,281 --> 00:34:43,116 Prasanna Malaiyandi: and I think this just goes back to humans make mistakes. 650 00:34:43,456 --> 00:34:44,276 You gotta back it up. 651 00:34:46,026 --> 00:34:48,606 W. Curtis Preston: Humans are the number one reason we back up. 652 00:34:51,036 --> 00:34:54,126 It's, I mean, that's been more, that is more true today 653 00:34:54,126 --> 00:34:57,756 than it ever was 30 years ago. 654 00:34:57,816 --> 00:35:00,456 The number one reason we were doing restores would be 'cause 655 00:35:00,456 --> 00:35:03,126 somebody deleted a file, right? 656 00:35:03,156 --> 00:35:07,206 They fat fingered a file, they fat fair, and get the current version of 657 00:35:07,206 --> 00:35:08,766 the file and they accidentally saved it. 658 00:35:09,066 --> 00:35:09,486 Right. 659 00:35:09,636 --> 00:35:09,726 Prasanna Malaiyandi: Yep. 660 00:35:10,596 --> 00:35:13,176 W. Curtis Preston: That, that was the number one reason we did 30 years ago. 661 00:35:13,176 --> 00:35:15,126 And every once in a while we would also lose a server. 662 00:35:15,126 --> 00:35:19,416 Because remember back then we didn't even have a raid, So if you lost a hard drive, 663 00:35:19,476 --> 00:35:20,196 Prasanna Malaiyandi: was very 664 00:35:20,346 --> 00:35:21,696 W. Curtis Preston: you lost a server, right? 665 00:35:22,446 --> 00:35:27,396 Um, you move 30 years up and it's still stupid. 666 00:35:27,396 --> 00:35:31,656 User errors and ransomware, which is another human caused 667 00:35:31,806 --> 00:35:33,396 reason that we do restores. 668 00:35:34,266 --> 00:35:34,896 Um, 669 00:35:35,076 --> 00:35:38,076 Prasanna Malaiyandi: Because also isn't most of the ransomware attacks started 670 00:35:38,136 --> 00:35:40,266 with phishing more than anything else. 671 00:35:40,491 --> 00:35:40,881 W. Curtis Preston: Yes. 672 00:35:41,121 --> 00:35:41,661 Yes. 673 00:35:41,706 --> 00:35:44,766 Prasanna Malaiyandi: it's an employee who accidentally clicks on a link 674 00:35:44,766 --> 00:35:45,786 that they shouldn't be clicking. 675 00:35:47,061 --> 00:35:47,511 W. Curtis Preston: Right. 676 00:35:47,901 --> 00:35:53,001 I, I saw, I'll, I'll, I'll tell a little story that I saw today on, um, on, um. 677 00:35:53,646 --> 00:35:58,416 TikTok and it was a guy who, like, he, he was like, he said, you would not 678 00:35:58,416 --> 00:36:02,196 believe what my wife's company did today. 679 00:36:02,256 --> 00:36:06,816 The video was actually made yesterday, so it's, this would be, uh, Valentine's Day. 680 00:36:07,536 --> 00:36:11,166 SO for those of you that don't know many companies, if not most companies do 681 00:36:11,166 --> 00:36:13,836 automated phishing tests, they send you. 682 00:36:14,256 --> 00:36:17,586 Emails that are essentially phishing emails to see if you will click on 683 00:36:17,586 --> 00:36:19,626 them or to see if you will notify them. 684 00:36:20,196 --> 00:36:27,156 And, um, he said they sent an automated email or they sent one of these testing 685 00:36:27,161 --> 00:36:31,656 emails to everyone in the company that said you have a Valentine's Day delivery 686 00:36:31,656 --> 00:36:33,666 from Edible Flowers at the front desk. 687 00:36:34,116 --> 00:36:35,316 And, uh, you know, 688 00:36:35,661 --> 00:36:36,321 Prasanna Malaiyandi: Click here. 689 00:36:36,486 --> 00:36:38,376 W. Curtis Preston: and then, and then there was a click, right? 690 00:36:38,916 --> 00:36:41,826 And he said for like, you know, a few minutes. 691 00:36:41,976 --> 00:36:48,336 Everyone in that company felt they were loved that, that they found out that 692 00:36:48,456 --> 00:36:48,876 Prasanna Malaiyandi: it was just, 693 00:36:49,086 --> 00:36:49,326 W. Curtis Preston: was a 694 00:36:49,326 --> 00:36:50,166 phishing email. 695 00:36:51,246 --> 00:36:54,306 Instead of getting love, what they got was yelled at by it. 696 00:36:54,546 --> 00:36:54,756 Prasanna Malaiyandi: And 697 00:36:54,756 --> 00:36:55,541 W. Curtis Preston: goes, accept. 698 00:36:56,256 --> 00:37:00,336 He said, accept my wife because my wife knew. 699 00:37:00,486 --> 00:37:06,426 There's no way I'm spending $200 on a, on some cantaloupe that's 700 00:37:06,426 --> 00:37:07,926 made to look like a flower. 701 00:37:09,756 --> 00:37:11,136 Prasanna Malaiyandi: That is hilarious. 702 00:37:12,186 --> 00:37:17,826 W. Curtis Preston: But yeah, that's just, I mean, the sad thing is, I mean, like I 703 00:37:17,826 --> 00:37:19,416 see both sides of this argument, right? 704 00:37:19,416 --> 00:37:20,406 Phishing emails. 705 00:37:21,711 --> 00:37:21,981 Right. 706 00:37:21,981 --> 00:37:25,911 They, they, they come, they, they are timed two things, right? 707 00:37:26,901 --> 00:37:29,811 They, they would, a, a bad guy would do this. 708 00:37:29,931 --> 00:37:33,801 They would leverage Valentine's Day, they would leverage Christmas, 709 00:37:34,191 --> 00:37:34,641 um, 710 00:37:34,806 --> 00:37:36,621 Prasanna Malaiyandi: at the company or something like that, right? 711 00:37:37,041 --> 00:37:37,911 W. Curtis Preston: exactly right. 712 00:37:38,556 --> 00:37:43,296 Um, and so on one hand I totally understand why they did, why they did 713 00:37:43,296 --> 00:37:46,146 what they did, but it's also messed up. 714 00:37:46,146 --> 00:37:49,116 And then this guy that posted it, there were a lot of comments and people were 715 00:37:49,121 --> 00:37:51,276 like, yeah, we were told we got a bonus. 716 00:37:51,456 --> 00:37:52,656 We were told we got this. 717 00:37:52,656 --> 00:37:53,706 We were told we got that. 718 00:37:53,706 --> 00:37:55,986 And it was all, uh, a phishing test. 719 00:37:57,426 --> 00:37:58,331 That's No, no, no, no. 720 00:37:58,356 --> 00:37:58,926 It was a phishing 721 00:37:58,926 --> 00:37:59,526 test. 722 00:37:59,586 --> 00:38:01,051 Like it was the. 723 00:38:04,041 --> 00:38:06,831 Prasanna Malaiyandi: And so instead of getting a bonus or Edible 724 00:38:06,831 --> 00:38:11,666 flowers, they get to go for a one hour training session on fishing. 725 00:38:13,286 --> 00:38:15,981 W. Curtis Preston: yeah, yeah. 726 00:38:16,761 --> 00:38:18,681 So you need to back up your stuff. 727 00:38:18,681 --> 00:38:20,931 You need to back up Microsoft 365. 728 00:38:20,936 --> 00:38:25,611 In this case, this is just the best, this is the current best example we have. 729 00:38:25,761 --> 00:38:28,131 If we have a new one, we'll make another episode. 730 00:38:28,581 --> 00:38:29,181 Um, 731 00:38:29,451 --> 00:38:29,841 Prasanna Malaiyandi: last. 732 00:38:30,201 --> 00:38:31,431 Oh, one last thing to add. 733 00:38:32,796 --> 00:38:37,296 Realize KPMG is a humongous company and they had issues. 734 00:38:37,656 --> 00:38:39,486 If you're a smaller company right? 735 00:38:39,486 --> 00:38:43,086 Don't feel bad that you're like, you haven't done anything yet, right? 736 00:38:43,236 --> 00:38:47,106 So, but now that you know, go figure out how you are gonna 737 00:38:47,106 --> 00:38:48,606 back up your SaaS applications. 738 00:38:48,606 --> 00:38:52,086 If you're using Microsoft 365, figure out how you are gonna back 739 00:38:52,086 --> 00:38:53,766 it up so you don't end up like KPMG. 740 00:38:54,951 --> 00:38:55,761 W. Curtis Preston: Absolutely. 741 00:38:56,001 --> 00:38:58,401 I will poorly quote Maya Angelou. 742 00:38:58,671 --> 00:39:01,851 We did what we did when we knew what we knew, and now we know better. 743 00:39:02,121 --> 00:39:02,871 We can do better. 744 00:39:03,651 --> 00:39:07,971 Uh, it's, it's a great quote, um, even if I didn't quite get it 745 00:39:08,061 --> 00:39:10,041 right, but that's Maya Angelou. 746 00:39:10,101 --> 00:39:11,181 May she rest in peace. 747 00:39:11,631 --> 00:39:12,651 Well, thanks persona. 748 00:39:13,191 --> 00:39:14,361 Another fun episode. 749 00:39:14,481 --> 00:39:14,961 Prasanna Malaiyandi: was fun. 750 00:39:14,961 --> 00:39:19,251 This was fun and I hope you sound a bit more cheerful now towards the end 751 00:39:19,491 --> 00:39:21,201 versus, uh, about five minutes ago. 752 00:39:21,201 --> 00:39:22,221 So that's a good sign. 753 00:39:22,221 --> 00:39:27,291 W. Curtis Preston: I was angry and thanks for those of you that are listening 754 00:39:27,501 --> 00:39:29,661 and, uh, look forward to some more. 755 00:39:29,901 --> 00:39:33,771 You should have backed up your stuff, episodes coming here in the 756 00:39:33,771 --> 00:39:36,531 coming weeks, and that's a wrap.