Security Hardening for Synology Microsoft 365 Backups
Security Deep Dive: Hardening Synology Microsoft 365 Backups
Microsoft 365 backups often contain some of an organisation’s most sensitive information, including executive email, financial documents, personnel records, customer data, SharePoint libraries, and Microsoft Teams content. Protecting the backup platform therefore requires more than simply configuring backup schedules. Administrators must secure credentials, restrict access, isolate the NAS, monitor activity, and keep both DSM and the Active Backup package current.
Synology Active Backup for Microsoft 365 provides centralised protection for Exchange Online, OneDrive, SharePoint Online, Microsoft Teams, shared mailboxes, and Microsoft 365 Groups. Its recovery portal also supports granular permissions, allowing ordinary users to access only their own backup data while administrators and users with restore privileges may access broader datasets.
A secure deployment should combine these built-in controls with layered infrastructure protection.
Learn from Past Security Issues
No backup platform should be treated as immune to vulnerabilities.
In May 2025, Synology disclosed CVE-2025-4679, a moderate-severity vulnerability in Active Backup for Microsoft 365 that could allow a remotely authenticated attacker to obtain sensitive information. Synology marked the issue as resolved and indicated that no customer action was required for the specific resolution.
The incident does not mean organisations should avoid the platform. It demonstrates why backup appliances require the same patching, access control, and monitoring discipline as other business-critical systems.
Administrators should regularly review:
-
Synology security advisories
-
DSM release notes
-
Active Backup package updates
-
Installed package status
-
Security Advisor findings
-
Unusual login or restore activity
Keeping software current reduces exposure to vulnerabilities that have already been identified and fixed.
Protect Microsoft 365 Application Credentials
Active Backup for Microsoft 365 uses a Microsoft Entra ID application and certificate to authorise access to Microsoft 365 data. Synology’s deployment guidance requires administrators to register or generate the application and certificate during task setup.
These credentials should be treated as privileged secrets.
Organisations should:
-
Limit access to the application registration
-
Store certificate passwords securely
-
Document certificate ownership and expiration
-
Remove unused applications and certificates
-
Review assigned Microsoft Graph permissions
-
Restrict who can modify backup authorisation
-
Use separate administrative accounts for backup operations
Microsoft 365 application credentials should never be stored in unsecured documentation, shared email accounts, scripts, or general-purpose password files.
Apply Least-Privilege Access
Not every administrator needs full access to every mailbox or document.
Synology allows organisations to distinguish between administrators, users with restore privileges, and standard portal users. Standard users can be limited to restoring or downloading only their own protected data.
A secure role design may include:
-
A limited number of DSM administrators
-
Dedicated backup operators
-
Separate recovery administrators
-
Self-service access for approved users
-
Read-only monitoring roles
-
Regular reviews of inactive accounts
Administrative accounts should not be used for routine file access or general office work.
Strengthen Authentication
Compromised credentials are a common route into backup infrastructure.
DSM supports password policies, automatic IP blocking, login alerts, multi-factor authentication, and adaptive MFA capabilities.
Organisations should enable:
-
Multi-factor authentication for administrators
-
Strong, unique passwords
-
Automatic blocking after failed logins
-
Login notifications
-
Account lockout policies
-
Centralised identity management where appropriate
Default administrator accounts should be disabled or renamed where supported, and access should be reviewed whenever employees or service providers leave the organisation.
Isolate the Backup Network
A Microsoft 365 backup NAS should not be openly reachable from every device or internet connection.
Recommended network controls include:
-
Placing backup systems on a dedicated VLAN
-
Restricting DSM access through firewall rules
-
Allowing management only from trusted networks
-
Using a VPN for remote administration
-
Blocking unnecessary inbound services
-
Separating user traffic from backup traffic
-
Avoiding direct internet exposure
The self-service recovery portal should be exposed only to the users and networks that genuinely require it.
Protect the Backup Repository
An attacker who compromises Microsoft 365 should not automatically gain access to its backups.
Organisations can replicate Active Backup for Microsoft 365 repositories to another Synology NAS using Snapshot Replication. Synology documents replication of the shared folder containing Microsoft 365 backup data to a remote system, creating an additional recovery location.
A layered design may include:
-
The primary Active Backup repository
-
Local snapshots
-
A replicated copy on another NAS
-
An off-site backup
-
Restricted credentials for each destination
-
Regular recovery testing
This helps prevent one compromised account, appliance, or location from eliminating every recovery option. Secure M365 backups with expert cyber security
Monitor and Audit Recovery Activity
Backup security also depends on visibility.
Administrators should review:
-
Failed login attempts
-
New administrative accounts
-
Permission changes
-
Unusual download activity
-
Large restore operations
-
Backup task failures
-
Certificate changes
-
Storage capacity alerts
Self-service recovery is valuable, but portal permissions should be tested to confirm that users can access only authorised information.
About Epis Technology
Epis Technology helps organisations secure Synology Microsoft 365 backup environments through infrastructure assessments, Active Backup deployment, credential reviews, access-control design, network segmentation, backup replication, cybersecurity hardening, recovery testing, and ongoing managed support. By combining Synology expertise with practical security planning, Epis Technology helps businesses protect sensitive backup data, reduce attack exposure, and maintain reliable recovery capabilities.