Skip to content

Backup

What is endpoint backup, and why does hybrid work need it?

Your servers and Microsoft 365 tenant are covered. The laptop on a train with this week's unsynced work usually isn't.

Unattended open laptop on a café table by a rainy window at dusk, showing how business data travels outside the office

The short answer

Endpoint backup copies the data stored on laptops and desktops, such as local files, unsynced drafts and application data, to separate storage you can restore from. Hybrid work puts more business data on devices outside the office, and sync tools like OneDrive only cover what reached the cloud. Endpoint backup closes that gap.

Key takeaways

  • SaaS backup only protects data that reached the cloud; files saved locally, outside synced folders or behind a paused sync client exist only on the device.
  • OneDrive Known Folder Move covers Desktop, Documents, Pictures, Screenshots and Camera Roll, and it syncs damage such as encrypted files as faithfully as good work.
  • Microsoft's shared responsibility guidance lists endpoints, alongside data and accounts, as a responsibility you always retain.
  • The Verizon 2025 DBIR found that 46% of compromised systems with corporate logins were non-managed devices holding both personal and business credentials.
  • A sound endpoint backup is automatic, encrypted, immutable, stored off the device, monitored for missed jobs and restore-tested.

What is endpoint backup and what does it cover?

Endpoint backup protects the data that lives on the device itself: user folders, locally stored application files and anything not yet uploaded. It fills the gap that server and SaaS backup leave.

Think of a sales manager who builds a pitch deck on a flight and saves it to the desktop, or an accountant who downloads ERP exports for offline analysis. If that laptop is stolen from a café in Utrecht tomorrow, the work is gone, because neither the Microsoft 365 backup nor the server backup ever saw it. That's why endpoints belong in your backup as a service plan alongside servers and SaaS.

DataSaaS backup (Microsoft 365, Google Workspace)Endpoint backup
Mailboxes, SharePoint, Teams, DriveYesNo
Files in synced folders that finished uploadingYesYes
Files outside synced foldersNoYes, if in scope
Unsynced changes and offline workNoYes, once backed up
Local application data and exportsNoYes, if in scope

You need both layers. Neither replaces the other.

Is OneDrive sync enough to back up laptops?

It helps, but it isn't enough on its own. Sync covers selected folders, can stop silently, and copies damage to the cloud as faithfully as it copies work.

Microsoft's Known Folder Move documentation explains that it redirects Desktop, Documents, Pictures, Screenshots and Camera Roll to OneDrive, and says that saving files there "backs up your users' data in the cloud". That's worth turning on. But three gaps remain:

  • Scope. Files saved elsewhere on the disk, and many application data folders, aren't redirected.
  • Silent failures. A paused or signed-out client can fall behind for days without the user noticing.
  • Replicated damage. If ransomware encrypts a synced folder, the encrypted versions sync to OneDrive and overwrite the good ones. Version history helps, but rolling back thousands of files is slow.

There's also a single point of failure: the synced copy lives in the same Microsoft 365 tenant as everything else. We explain that risk in does Microsoft 365 back up your data? Microsoft's own shared responsibility in the cloud page lists endpoints, meaning laptops, desktops and mobile devices, as a responsibility you always retain.

What risks do laptops create in a hybrid workforce?

Three stand out: theft or loss, ransomware that starts on the device, and personal devices that mix work and private data.

Theft and loss

A lost laptop is a hardware problem and, if it held personal data, possibly a data breach. GDPR Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a breach that's likely to pose a risk. Under Article 34(3)(a), you may not have to inform affected individuals if the data was rendered unintelligible, for example by encryption. Full-disk encryption plus a backup turns theft into a replacement job.

Ransomware

According to Verizon's 2025 Data Breach Investigations Report, ransomware was present in 44% of breaches analysed, and in 88% of breaches at small and medium-sized businesses. Endpoints are often where it starts, and local files are among the first things it encrypts.

Bring your own device

The 2025 DBIR executive summary found that "46% of those compromised systems that had corporate logins in their compromised data were nonmanaged and were hosting both personal and business credentials", which Verizon links to BYOD programmes or company devices used outside policy. Unmanaged devices are harder to protect, monitor and back up.

How should you handle BYOD devices?

Keep company data in places you control, and back up only work data on personal devices. Backing up an employee's whole personal laptop creates privacy problems of its own.

  1. Prefer managed devices for sensitive roles. Finance, HR, legal and leadership handle the most sensitive data and travel the most.
  2. Containerise work on personal devices. Use managed work profiles or browser-only access so company data stays in synced, backed-up locations.
  3. Limit backup scope. On a personal device, cover defined work folders only, in line with GDPR's data minimisation principle in Article 5(1)(c).
  4. Tell people what's covered. Explain that the backup protects work files, not personal photos. Transparency prevents the feeling of surveillance.

What should an endpoint backup policy include?

A one-page policy that sets scope, frequency, retention, security and testing. It's what auditors and insurers ask to see, and it keeps everyone's expectations aligned.

Policy elementWhat to decide
ScopeWhich company devices are covered, and which work profiles on BYOD devices
CoverageProfile folders and approved application data; operating system images usually not
Frequency and RPOHow much work each role can afford to lose, which sets how often backups run
RetentionHow long versions are kept, matched to legal and business needs
SecurityEncryption, immutable storage, location of the backup copy and who can restore
Recovery and RTOHow quickly a user gets critical files back on a replacement device
VerificationAlerts on devices that miss backups, plus regular test restores

RPO is how much work you can afford to lose; RTO is how long you can be without it. Our RTO and RPO guide explains how to set both. For organisations in scope of NIS2, Article 21(2)(c) requires "business continuity, such as backup management and disaster recovery", and laptops that process business data are part of the systems it covers.

How do you roll out endpoint backup?

Start with the most exposed users, automate everything, and prove it works with test restores. Users shouldn't have to do anything.

  1. Pick a pilot group. Executives, finance and travelling staff carry the highest-value data.
  2. Deploy agents centrally. Use your device management or RMM tooling so installation and policy are consistent.
  3. Store copies off the device and immutable. Follow the 3-2-1-1-0 rule, so malware on the laptop can't reach the backup.
  4. Monitor for missed backups. A device that hasn't checked in for a week is a silent risk.
  5. Test restores. Restore a sample of devices to new hardware each quarter and record the result. See how to verify your backup works.

Mindtime endpoint backup stores copies only in our own Tier III data centres in the Netherlands and Germany, under EU law. Data is AES-256 encrypted in transit, backups are immutable with Object Lock plus an air-gapped copy, scanned for malware, and every backup job is checked automatically and monitored 24/7. MSPs manage all clients from one multi-tenant console, and can pair backup with our EDR platform for endpoint detection they run themselves.

What to do next

Hybrid work moved business data onto hundreds of laptops, and most backup plans stopped at the server room and the cloud tenant. Closing the gap is well understood: automatic, encrypted, immutable endpoint copies stored off the device, governed by a short policy and proven with test restores.

Start by asking one question: if ransomware hit fifty remote laptops on Monday, what would you restore from, and how long would it take? Then see how endpoints fit into your wider backup as a service setup.

Book a free 15-minute demo and we'll show you an endpoint restore to a replacement laptop.

This article is information, not legal advice.

Frequently asked questions

Does Microsoft 365 backup cover data on laptops?

No. A Microsoft 365 backup protects data in the tenant: Exchange mailboxes, OneDrive, SharePoint and Teams. Files saved only on the laptop, outside synced folders or stuck behind a paused sync client, are invisible to it. Full coverage needs both a SaaS backup for cloud data and an endpoint backup for data on the device.

Is OneDrive a backup for laptops?

Partly. Known Folder Move syncs Desktop, Documents, Pictures, Screenshots and Camera Roll to OneDrive, which protects against a lost device. But sync also copies deletions and ransomware-encrypted files, only covers those folders, and keeps the copy in the same Microsoft 365 tenant. A separate, immutable endpoint backup covers those gaps.

What happens to my data if a laptop is stolen?

With endpoint backup, the files are safe in storage independent of the device, and the user can restore them to replacement hardware. If the laptop held personal data and wasn't encrypted, GDPR may require you to notify the supervisory authority within 72 hours. Full-disk encryption on the device reduces that risk considerably.

Should I back up employees' personal devices?

Only the work data. On a BYOD device, limit backup to defined work folders or a managed work profile, and tell employees what's covered and what isn't. Backing up a whole personal device captures private data you don't need, which conflicts with GDPR's data minimisation principle. For sensitive roles, a company-managed device is usually the better choice.

How often should endpoint backups run?

That depends on how much work each role can afford to lose, your recovery point objective. Someone editing contracts all day needs more frequent backups than a device used for email. Set the frequency per role in your backup policy, make sure the agent catches up automatically after travel or sleep, and alert on devices that miss backups.

Sources

  1. Redirect and move Windows known folders to OneDriveMicrosoft Learn, 2025
  2. Shared responsibility in the cloudMicrosoft Learn, 2026
  3. 2025 Data Breach Investigations Report: news releaseVerizon, 2025
  4. 2025 Data Breach Investigations Report: executive summaryVerizon, 2025
  5. Regulation (EU) 2016/679 (GDPR)EUR-Lex, 2016
  6. Directive (EU) 2022/2555 (NIS2)EUR-Lex, 2022
Part ofBackup as a Service