Non-destructive restore by default
Restore in Osiris is granular or complete (a single email, a folder, a file, a specific file version, or an entire mailbox or OneDrive), into the original account or a different one. By default it does not overwrite anything that already exists: it writes new items rather than silently replacing live data, because the one thing worse than a missing backup is a restore that destroys something that wasn't actually lost. The current beta still ships an explicit "Replace" mode behind a warning for mail and OneDrive restores: see below for exactly what that means and where it's going.
Self-service, and restore for others
Today, end users sign in with a passkey or the emergency password with TOTP and can restore only their own mailbox or OneDrive, with no admin ticket required for the common case. Signing in with a Microsoft account through Entra OIDC is built into Osiris but not enabled yet: the button exists, but ownership today would be bound to the email claim alone, with no verified Microsoft tenant/user binding: a real security gap this project is not willing to ship, not just a flag to flip. Restoring on someone else's behalf needs the Global Admin role for that tenant, or a Provider Admin role in the Service Provider edition; every such restore is impersonation, and every impersonation is written to Osiris's tamper-evident, hash-chained audit log: who ran it, when, for whom, and from which IP.
Where "non-destructive by default" is going next
Today, an explicit "Replace" restore mode exists for the narrow case where overwriting is actually the intent. It is planned to be removed entirely, so that overwriting an existing original becomes structurally impossible in the product, not just a mode you have to avoid clicking. Full, per-item restore verification (reading back and checking every backed-up item, not a weekly sample) is the other piece of "restore that's actually proven," covered on theverification page.
Frequently asked
Can an Osiris restore overwrite my existing mail?
By default, no. Restore writes items into the target (the original account or a different one) rather than silently replacing what's already there. The current beta still offers an explicit "Replace" mode behind an on-screen warning, for the rare case overwriting is actually wanted; it is being removed entirely as a planned change, so overwriting becomes structurally impossible rather than just discouraged.
Who can restore data for someone else?
Today, end users sign in with a passkey or the emergency password with TOTP and can only restore their own mailbox or OneDrive. Signing in with a Microsoft account (Entra OIDC) is built but not enabled yet: the button exists, but the tenant/ownership binding behind it (today, tied to the email claim alone) isn't safe to turn on. Restoring on behalf of another user needs the Global Admin role for that tenant, or Provider Admin, and every such restore (impersonation) is written to Osiris's tamper-evident, hash-chained audit log: who, when, for whom, from which IP.
What can be restored: a whole mailbox, or a single email?
Both, and everything in between: a single email, a folder, a file, a specific file version, or a complete mailbox/OneDrive, from any point Osiris has a backup for.