Skip to content
SharePoint Solutions & Products

A Customer-Controlled SharePoint Archive in Azure

Why Keepit and Microsoft 365 Backup remain valuable protection layers while a customer also required a directly controlled SharePoint archive copy in Azure.

Updated
Archive Workspace showing SharePoint sites, archive status, file volumes, and reports

The customer already used Keepit to protect Microsoft 365. Deleted or accidentally changed content could be restored. The new requirement did not arise from a missing backup, but from a different question:

Can we administer, access, and operate the archive copy of completed SharePoint projects under our own rules?

The customer did not want to use completed project data solely through a backup service’s storage, access, and commercial model. The additional archive copy had to reside in an Azure subscription administered by the customer, with direct control over the storage account, access, retention, lifecycle, and cost.

That is the form of customer control this project set out to provide.

Backup, data residency, and customer control are different requirements

Keepit and Microsoft 365 Backup each follow a coherent protection model:

Both approaches protect data and support recovery. Neither automatically creates the specific file copy in a customer-selected Azure Storage account that the customer can manage through its own RBAC, network, and governance model.

This is not a judgement on the quality of either backup product. It is a different operating model:

RequirementOperational backupCustomer-controlled project archive
Recover deleted or changed contentprimary purposenot the primary purpose
Historical recovery pointsdepends on product scopenot included
Archive files in the customer’s Storage accountnot automaticyes
Direct access through customer-managed Azure rolesfollows the service modelyes
Customer-defined storage tier, lifecycle, and costfollows the service modelin the customer subscription
Formal handover of completed projectsmay complement the servicecore workflow

The customer’s specific requirement

Completed SharePoint project sites contained technical documentation, plans, and commercial records. The content changed rarely, but still had to remain searchable, traceable, and economical to retain.

The customer defined six clear goals:

  1. Only completed and approved projects are transferred.
  2. Archive files reside in the customer’s Azure subscription.
  3. Permissions, network access, and monitoring follow customer standards.
  4. Administrators can find and download files without restoring them first.
  5. Every run records scope, volume, errors, and unresolved work.
  6. SharePoint remains unchanged during the initial pilot.

The final point matters. Customer control does not come from deleting the source as quickly as possible. It begins with a complete, verifiable, and usable additional copy.

How the Archive Workspace meets that requirement

We implemented the requirement as a dedicated product workflow:

  1. An administrator selects a configured SharePoint site and its approved libraries.
  2. The Archive Workspace starts a durable background run; the browser does not need to remain open.
  3. The solution checks scope, completeness, and stored file content and records discrepancies in a report.
  4. Authorised administrators can then search the archive by file name or path and download files or folders as ZIP.

Archive Workspace showing archived sites, status, file volumes, and reports

Archive objects and technical evidence reside in the customer’s Azure environment. The archive can therefore use the customer’s existing role, network, monitoring, and cost-management model.

The implementation behind durable jobs, safe retries, byte verification, and consistent reports belongs in part 2.

What value does the customer receive?

Direct control over the archive copy

The customer administers the Azure resources that hold the archive files. It grants access, defines lifecycle rules, and sees the resulting Storage costs in its own subscription.

An additional access path

Keepit continues to provide operational recovery. The project archive adds direct file-based access to completed project data. An administrator does not have to restore an individual archive file into SharePoint first.

Traceable project closeout

A site is not considered archived merely because some Blobs exist. Each run has an approved scope, reports every discrepancy, and ends with evidence that business owners and IT can review together.

Transparent cost control

Rarely used project data can use Azure Storage tiers and lifecycle rules. These policies belong to the customer’s Azure governance and remain separate from the archive application.

Less dependence on a single access model

The archive does not replace a backup service. It prevents access to completed project documentation from depending exclusively on that service’s portal, data format, and operating model.

What the solution deliberately is not

The Archive Workspace is neither a replacement for Keepit or Microsoft 365 Backup nor a complete SharePoint image.

It archives the current bytes of discovered files. Version history, list fields, pages, empty folders, original permissions, workflows, and site configuration are outside the product scope. Regulatory retention, cross-region availability, and contractual recovery-time commitments also remain separate requirements.

In addition to copy-only, the product supports controlled deletion, verified replacement links, and optional read-only state. We still recommend copy-only for the initial rollout. Only after the technical report, business sample, and archive access have been accepted should the customer consider changing the source.

Conclusion

The requirement was not “another backup”. The customer wanted direct control over the archive copy: in its Azure subscription, under its access model, with its retention rules, and with a direct path to the files.

Keepit continues to protect day-to-day Microsoft 365 operations. The Archive Workspace adds a customer-controlled SharePoint project archive.

Part 2 covers the main engineering lessons. Part 3 explains approval, acceptance, and safe rollout.

Would you like to assess whether this control model fits your SharePoint estate? Start with one completed test site.

  • SharePoint Online
  • Azure
  • Archiving
  • Keepit
  • Microsoft 365 Backup
  • Data Control

Related articles

SharePoint Archiving: 7 Engineering Lessons
Archive Workspace showing SharePoint sites, archive status, file volumes, and reports

SharePoint Archiving: 7 Engineering Lessons

What we learned about discovery, retries, concurrency, integrity, and consistent evidence while building a customer-controlled SharePoint archive.

Read more
SharePoint Intranet Phone Directory with a Skills
SharePoint Intranet Phone Directory with a Skills Feature

SharePoint Intranet Phone Directory with a Skills Feature

Build SharePoint people and skills search with SPFx, Microsoft Graph, a skills catalog, and Microsoft 365 profile data.

Read more

Questions about this topic?

We are happy to help you put this into practice in your environment.