Tenant configuration, not user data

Every Microsoft 365 setting, saved.
And put back when it matters.

365 Rewind saves the configuration of your tenant: policies, connectors, filters, allow and block lists and settings. Compare two backups to see exactly what changed, and restore a single item to the way it was.

Mail, files and chats are never read Backups use read-only permissions A restore never deletes anything
Wide

coverage: every type of configuration in the catalog is backed up and compared, across the Microsoft 365 workloads

Read-only

backups read the tenant and change nothing; a restore uses a separate sign-in

AES-256-GCM

backups are encrypted on your machine before they are stored, hosted or local

Item by item

restore one policy or fifty; what you did not select is left alone

What it covers

Every workload. One backup.

The settings that decide who can sign in, where mail flows and what is blocked. The things that are painful to rebuild from memory.

Entra ID

Conditional Access policies, named locations, authentication methods and strengths, security defaults, guest and consent settings, cross-tenant access.

Exchange Online

Mail flow rules, inbound and outbound connectors, accepted and remote domains, DKIM signing, organization and transport settings.

Defender

Anti-phishing, anti-spam and anti-malware policies and rules, Safe Links and Safe Attachments, the tenant allow and block list.

Purview

Retention and data loss prevention policies, sensitivity labels and label policies, audit settings.

SharePoint and OneDrive

The tenant-wide sharing and access settings that Microsoft Graph exposes. Site-level configuration follows later.

Teams

Meeting, messaging, calling and channel policies, guest and external access settings, client settings.

The catalog grows: Intune, Power Platform and the Microsoft 365 admin center are being added. The coverage page lists every area of every admin center after you sign in, including the areas that no product can back up today.

Backup coverage is wide. Restore coverage grows.

Every type is backed up and compared from the start. Restore is switched on for a type only when it has been proven against a live tenant, so the number of types the app can restore grows with each release. Until then a walk-through takes you through putting the saved values back by hand.

See what is covered

  • –
    Restored in fullChanged items are updated and missing items are recreated.
  • –
    Settings put backFor tenant-wide settings and built-in objects: the saved values are put back on the object that still exists.
  • –
    Restored by handBacked up and compared. A walk-through shows each saved value beside the current one, and where to find the setting in the admin center.
Storage

You choose where backups live.

Per tenant, and you can change it later. The choice applies to future backups.

Hosted

Encrypted on your machine, uploaded, and kept encrypted in the portal.

  • Browse and compare in the browser
  • Prepare restores in the portal
  • The storage key is kept apart from the database

Local vault

Kept in a folder you choose, encrypted with a key protected by Windows.

  • The portal sees counts only: no names, no settings
  • Browse, compare and restore in the Windows app
  • A recovery key lets you open the vault on another machine
Restore

Put it back the way it was.

You pick the items, and you choose how they go back: the Windows app applies them as you, a script does it under your own eyes, or you make each change by hand.

  1. Pick the items

    Open a backup or a comparison and check what you want back: one policy, a connector, a handful of rules.

  2. Review the plan

    The plan lists the items in the order they will run, and the roles and permissions the restore will ask for.

  3. Run it your way

    In the Windows app, with a separate sign-in that asks only for what those items need. With a restore script that you read and run yourself, and that previews first. Or by hand, with a walk-through.

  4. Check the result

    Each item reports what happened. The next backup confirms that the tenant matches what was restored.

Safe by design

A restore should never make things worse.

These rules are built into the app. They are not options you have to remember to switch on.

Nothing is deleted

Items that exist in the tenant but not in the backup are reported, never removed.

Risky items come back switched off

A recreated Conditional Access policy returns in report-only mode; mail flow rules, connectors and threat policy rules return disabled. You turn them on when you have checked them.

Every change can be rolled back

The app records the state before and after each item in a journal on your machine and can undo the restore from it.

It stops at the first failure

If an item fails, the restore stops there and says so. It does not press on and hope.

Your sign-in, your permissions

The app runs as the administrator who signed in. Tokens stay in memory, are never written to disk and are never sent to the portal.

Plans carry data, not commands

A restore plan holds the saved settings only. How they are applied is fixed in the app. The restore script is one fixed file that you can read; your settings travel in it as data, never as commands.

Already have a workspace?

Sign in to see your tenants, their backups and what changed.

Sign in