Mario Leiva, specialist in architecting high-availability data protection frameworks across North America, Australia and Europe
Most organizations assume their SaaS data is protected. It isn’t. Microsoft’s own service agreement is explicit: protecting your content and data within Microsoft 365 is your responsibility, not Microsoft’s. Salesforce follows the same shared responsibility model. Yet according to the 2025 State of SaaS Backup and Recovery Report — a survey of over 3,700 IT professionals — 87% experienced a SaaS data loss incident in the past 12 months. Only 53% of organizations have a dedicated backup strategy for Salesforce, and the recycle bins that most organizations rely on for recovery retain data for just 30 to 93 days.
At the same time, infrastructure environments have expanded. Modern organizations run a combination of on-premises servers, cloud VMs, databases, and SaaS applications — each with its own protection requirements. Managing them through separate point tools creates the SaaS infrastructure gap: a fragmented estate where visibility is partial, policies are inconsistent, and recovery outcomes are unpredictable.
Commvault systems close that gap by unifying SaaS application protection, identity directory backup, and hybrid infrastructure recovery into a single platform. ThinkOn delivers those Commvault systems as a fully managed, multi-tenant service built for the North American channel.
Glossary
Commvault systems: The collective set of Commvault data protection capabilities — backup, recovery, immutability, ransomware defense, and compliance controls — delivered through Commvault Cloud as a unified platform covering SaaS, cloud, and on-premises workloads.
SaaS infrastructure gap: The protection blind spot that occurs when SaaS applications (Microsoft 365, Salesforce, Entra ID) and on-premises or cloud infrastructure are managed through separate, disconnected backup tools — creating inconsistent policies, fragmented visibility, and unreliable recovery.
Shared responsibility model: The division of data protection duties between a SaaS vendor and its customers. The vendor is responsible for platform availability; the customer is responsible for protecting their data within that platform.
Entra ID backup: Protection of Microsoft Entra ID (formerly Azure Active Directory) directory objects, group memberships, and conditional access policies — which are not automatically backed up to a recoverable state by Microsoft.
Immutable backup: A backup copy protected by object lock, preventing it from being altered, encrypted, or deleted for a defined retention period — even by attackers with administrative credentials.
RPO (Recovery Point Objective): The maximum acceptable amount of data loss measured in time. A four-hour RPO means no more than four hours of data can be lost in a recovery event.
RTO (Recovery Time Objective): The maximum acceptable time to restore systems after an incident. A lower RTO means faster recovery and less business disruption.
What is the main difference between Commvault’s data protection offerings and other backup solutions nowadays?
Commvault systems unify Microsoft 365, Salesforce, Entra ID, and hybrid infrastructure into one platform — eliminating the fragmented tool stack most competitors require.
Traditional backup solutions are built workload by workload — one product for VMs, another for Microsoft 365, another for Salesforce. Each adds a separate console, a separate retention policy, and a separate billing line. Commvault systems replace that stack with a single platform that applies consistent protection, recovery verification, and compliance documentation across every workload type. For MSPs, that means one audit trail and one invoice regardless of client complexity. For enterprise IT teams, it means one recovery answer when an incident occurs.
What is the SaaS infrastructure protection gap?
The SaaS infrastructure gap is the unprotected space between what SaaS vendors cover and what organizations assume they cover — a gap that grows wider as SaaS adoption accelerates.
Microsoft manages platform availability, backend infrastructure, and uptime for Microsoft 365. It does not protect against accidental deletion, ransomware encryption, misconfiguration, or data loss caused by departing employees. The native recycle bin retains deleted items for 30 days in Exchange Online and 93 days in SharePoint — and ransomware attackers routinely clear these bins on entry. Microsoft’s own documentation states: “You own your data and identities. You are responsible for protecting the security of your data and identities.”
Salesforce takes the same position. Salesforce’s $1.9 billion acquisition of Own in 2024 — now offered as Salesforce Backup & Recover — validates rather than negates this: even Salesforce recognizes that its platform does not constitute backup.
For Entra ID, the gap is more acute. Microsoft’s native recycle bin recovers soft-deleted objects for 30 days. Microsoft’s own 2024 Digital Defense Report found it takes an average of 207 days to detect and resolve a data incident — meaning by the time a problem is identified, the recovery window has long expired.
Organizations running Microsoft 365, Salesforce, Entra ID, and hybrid infrastructure through separate point tools face inconsistent retention policies, fragmented billing, and no single view of their overall protection posture. That’s the gap Commvault systems are built to close.
What are Commvault systems and what do they protect?
Commvault systems are the unified set of data protection capabilities covering SaaS applications, identity directories, and hybrid infrastructure from a single platform — applying consistent policies, retention, and recovery verification across every workload.
| Workload | What Commvault systems protect |
|---|---|
| Microsoft 365 | Exchange Online, SharePoint, OneDrive, Teams — beyond native recycle bin limits |
| Salesforce | Objects, files, metadata, and chatter — independently of Salesforce’s native tools |
| Microsoft Entra ID | Directory objects, group memberships, conditional access policies |
| On-premises servers and VMs | VMware, Hyper-V, physical servers, NAS |
| Cloud infrastructure | AWS, Azure, Google Cloud VMs and databases |
| Databases | SQL Server, Oracle, SAP HANA, PostgreSQL |
| Endpoints | Windows and macOS laptops and desktops |
| Kubernetes | Container workloads and persistent volumes |
The unifying principle across all of these is that Commvault systems apply consistent protection policies, retention schedules, and recovery verification across every workload — not just the ones that have dedicated point tools. Commvault has been named a Leader in the Gartner Magic Quadrant for Backup and Data Protection Platforms for 14 consecutive years, and was the only vendor to score 4.0 or higher out of 5 across all six use cases in the 2025 Gartner Critical Capabilities report — including SaaS, Hybrid, Disaster Recovery, and Ransomware Protection.
How do Commvault systems handle the Microsoft 365 and Salesforce protection gap?
Commvault systems extend protection beyond what Microsoft and Salesforce cover natively — providing independent, policy-driven backup with point-in-time recovery, immutability, and compliance documentation that native tools cannot deliver.
For Microsoft 365, Commvault systems back up Exchange Online, SharePoint, OneDrive, Teams, and Entra ID to an independent, immutable repository. Unlike Microsoft’s native recycle bin, Commvault backup is not subject to the 30–93 day retention limits, is not clearable by ransomware attackers, and is not dependent on Microsoft’s platform availability. Point-in-time recovery means any item — an email, a SharePoint page, a Teams message, an Entra ID object — can be restored to a precise historical state.
For Salesforce, Commvault systems protect objects, files, metadata, and chatter independently of Salesforce’s native tools. Only 41% of organizations use a third-party tool to protect their Salesforce data — the majority are relying on a platform whose vendor explicitly states customers are responsible for their own data.
For Entra ID specifically, Commvault backup captures directory objects, group memberships, and conditional access policies on a schedule that far exceeds the 30-day native recovery window. For organizations subject to SOC 2, HIPAA, or financial services regulations, this independent backup is the only way to satisfy point-in-time recovery and long-term retention requirements.
How do Commvault systems protect against ransomware across SaaS and infrastructure?
Commvault systems layer immutable backups, air-gapped storage, and isolated Cleanroom Recovery to prevent ransomware from reaching or compromising backup data across all workloads — SaaS and infrastructure alike.
Immutable backup copies. Object lock-based immutability prevents backup data from being encrypted or deleted during the retention period — enforced at the storage layer, not the application layer. This applies equally to Microsoft 365 backup and on-premises VM backup.
Air-gapped storage. Commvault supports air-gapped backup targets including ThinkOn’s hardened repository infrastructure, physically isolating backup copies from the production network and from the SaaS platforms being protected.
Cleanroom Recovery. Launched in 2025, Commvault’s Cleanroom Recovery capability stages data in an isolated environment for forensic verification before reintroduction to production — preventing the reinfection loop that affects organizations without a verified recovery step.
Ransomware attacks targeted backup repositories in 96% of incidents in 2024 and successfully compromised them 76% of the time (Veeam 2024 Ransomware Trends Report). For organizations whose SaaS data and infrastructure backup lives in the same unverified environment, that statistic applies across the entire estate. Commvault systems address it at the architectural layer.
How does ThinkOn deliver Commvault systems as a managed service?
ThinkOn delivers Commvault systems as a fully managed, multi-tenant service — covering SaaS and infrastructure under one portal, with sovereign data residency, no egress fees, and predictable per-workload billing.
ThinkOn’s Data Protect with Commvault Cloud service gives channel partners and enterprise clients access to the full suite of Commvault systems without provisioning or maintaining the underlying infrastructure:
Unified SaaS and infrastructure portal. Microsoft 365, Salesforce, Entra ID, VMs, and databases are managed through the same Commvault portal — one set of policies, one billing line, one audit trail.
No infrastructure to manage. ThinkOn provisions and operates the underlying compute, storage, and licensing. Engineering time goes to client delivery, not platform maintenance.
Sovereign North American data residency. Data remains within ThinkOn’s regional infrastructure with contractual residency commitments — relevant for clients in healthcare, financial services, and legal where data sovereignty is a compliance requirement.
Predictable per-workload billing. Transparent pricing per workload with no egress fees on restores and no minimum duration charges.
Continuous recovery verification. Automated restore testing confirms recovery outcomes across every workload — SaaS and infrastructure — on an ongoing basis, producing auditable evidence of recoverability.
Commvault systems vs. point tools: the protection gap in practice
| Commvault systems | Point tools per workload | |
|---|---|---|
| Microsoft 365 coverage | Full — Exchange, SharePoint, OneDrive, Teams, Entra ID | Partial — varies by tool |
| Salesforce backup | Native within Commvault | Requires separate product |
| Entra ID recovery window | Policy-defined, beyond 30-day native limit | Depends on tool |
| Ransomware protection | Immutable + air-gapped + Cleanroom Recovery | Varies — often absent |
| Recovery verification | Automated, continuous, documented | Manual, infrequent |
| Billing model | Single per-workload invoice | Multiple vendor contracts |
| Compliance documentation | Unified audit trail across all workloads | Fragmented per tool |
Key statistics and sources
- 87%of IT professionals experienced a SaaS data loss incident in the past 12 months (2025 State of SaaS Backup and Recovery Report)
- Only 41%of organizations use a third-party tool to protect Salesforce data — the majority run Salesforce without backup (Expert Insights SaaS Backup Stats 2025)
- 30–93 days— Microsoft 365 native recycle bin retention window; not a recovery plan (AvePoint, 2025)
- 207 daysaverage time to detect and resolve a data incident — far beyond the native Entra ID recovery window (Microsoft Digital Defense Report 2024)
- 96% / 76%of ransomware attacks target backup repositories; 76% successfully compromise them (Veeam 2024 Ransomware Trends Report)
- 14 yearsconsecutive Gartner Magic Quadrant Leader for Backup and Data Protection Platforms (Commvault, 2025)
Sources: 2025 State of SaaS Backup and Recovery Report; Expert Insights SaaS Backup and Recovery Stats 2025; AvePoint Microsoft 365 Shared Responsibility Model; Microsoft Digital Defense Report 2024; Veeam 2024 Ransomware Trends Report; Gartner Magic Quadrant for Backup and Data Protection Platforms 2025.
