Blog / Playbooks

Data loss playbooks

IT isolating a workstation during a cloud file incident

Match what you see to a timed runbook. Freeze first. Restore to a side path. Do not rebuild a same-name folder while the original might still be recoverable.

These checklists walk native Microsoft 365 and Google tools first — Recycle Bin, Trash, version history, deleted-user restore — then independent copies when those windows close. They are for helpdesk and tenant admins under pressure, not product comparisons.

Start with classification: empty on the PC but present in the browser is usually sync. Wrong file contents is version history. An entire site or Shared Drive is a container incident. Encryption spreading through a sync client is ransomware. Use the table below rather than guessing from memory.

If you see thisOpen
Folder looks empty on the PC, but you have not confirmed the web appDeleted files or a sync conflict?
The file is still there, but the contents are wrong or overwrittenRestore from version history
Many files or mail items disappeared at onceFirst 60 minutes after a mass delete
Files renaming, encrypting, or spreading through the sync clientFirst 4 hours of OneDrive or Drive ransomware
An entire site, library, or Shared Drive is gone — not one folderSharePoint site or Shared Drive vanished
Google Drive items are in Trash or just left Trash; Takeout will not help in timeGoogle Drive files deleted (without Takeout)
HR or helpdesk deleted the account and someone still needs the mailMailbox after a user was deleted
Trash, Recycle Bin, and deleted-user restore are already emptyNative recovery windows have expired
You are not in an incident — you need to prove restore still works90-minute restore drill

Practice before you need them: the 90-minute restore drill is P3 on purpose. After an incident, come back to the hub rather than searching the whole blog.