The 3-2-1 backup rule still applies when primary data lives in SaaS: you need at least three copies, on two different media, with at least one offsite. For SaaS this typically means the production copy stays with the provider while you keep two independent exported copies. This article shows what to export, where to store each copy, how often to export, how to verify restores, and how to troubleshoot incomplete or corrupted exports.

What to export (and what to leave in the provider)

Decide by business value, legal needs and recoverability. Prioritise exports for items that would harm operations if lost:

  • Emails, calendars and contacts — user mailboxes and group calendars. These are often required for legal or continuity purposes.
  • User files — OneDrive, Google Drive, shared drive and site libraries (SharePoint, Drive team folders).
  • Configuration and membership data — user lists, group membership, role mappings, DNS records or app settings that are hard to reconstruct.
  • Critical application exports — accounting, CRM and ticketing data when the app cannot guarantee recoverable history or you need long-term retention.
  • Avoid exporting purely transient or disposable items unless policy requires it.

Important: copying a live database or file store is not automatically application-consistent. Prefer provider APIs or built-in export features that produce consistent snapshots or logical exports (PST/mbox, zipped site snapshots, JSON/CSV exports).

Applying 3-2-1 to SaaS exports

Treat the SaaS provider copy as the first copy. Your two additional copies might be:

  1. Onsite copy — a regularly scheduled export stored locally (NAS or external disk) for fast restores. If you use AgooCloud for Windows backups, local or server-routed destinations are a practical onsite target; note local backups do not consume cloud quota.
  2. Offsite copy — a cloud destination different from the SaaS provider (AgooCloud cloud destination or other). Keep this logically separate and monitored.

Optionally keep a third, offline archive (rotated external drive or air-gapped storage) to withstand ransomware or credential compromise.

Media diversity and isolation

Use different storage types: local disk/NAS, a different cloud provider, or removable media. Aim for at least one copy that is not directly addressable with your regular user credentials (offline or archival) to reduce ransomware risk.

Sample export schedules

Adjust frequency to your business RPO/RTO and the type of data.

  • Critical mailboxes: incremental backups (changes) daily; full export weekly; keep rolling snapshots for 30–90 days, archive quarterly.
  • Drive/OneDrive/Google Drive files: incremental file sync daily (or more often if volume justifies); verify weekly; monthly full exports for long-term retention.
  • Calendars and contacts: daily or weekly exports depending on change rate; retain several months to address deletion events.
  • Application data (CRM, accounting): daily exports for transactional systems; longer retention for historic legal requirements.

When possible prefer changed-block/changed-chunk exports or delta APIs to reduce bandwidth and speed up transfers. For initial seeding of very large datasets, consider offline transfer methods supported by your tools or schedule initial exports during low-traffic windows.

Automate where possible; document when manual

  • Use provider export APIs, scheduled data exports or third-party connectors to automate retrieval and delivery to your chosen stores.
  • If manual exports are required, document every step in a runbook: who runs it, how to name files, where to place them, and how to verify.
  • Log each export (size, checksum, start/end time, exported accounts). Store those logs with the archive for audit and troubleshooting.

Checklist for secure transfer and storage

  • Use encrypted transport (TLS) or SFTP when moving exports between services.
  • Store exports encrypted at rest. If available, use client-side encryption for sensitive exports; remember this affects your ability to restore without keys.
  • Handle export passwords and keys with a dedicated password manager and limited access — rotate credentials periodically.
  • Apply least privilege: create service accounts for exports with only required API scopes.
  • Name files with clear timestamps and include export metadata (source, type, account) in filenames and logs.

Verification and restore testing

Exports are only useful if restorable. Regularly test partial and full restores:

  • Run quarterly restore drills for representative mailbox, file and configuration restores.
  • Validate exported archives with checksums (SHA256) and compare to logs after every export.
  • For mail exports, import a sample into a test account; for file exports, restore to a test folder and verify file integrity and metadata.
  • Document restore procedures and estimated recovery time objectives (RTOs).

Troubleshooting incomplete or corrupted exports

  • Symptoms: missing messages/files, truncated archives, verification checksum mismatch, export job errors.
  • Check API tokens and service-account permissions first — expired or insufficient scopes commonly cause failures.
  • Inspect export logs for rate-limit or quota errors. Large exports can be throttled or time out; re-run in smaller batches if needed.
  • Confirm destination storage has sufficient space. (Note: AgooCloud local backups do not consume cloud quota when stored locally; monitor offsite quota separately.)
  • If an archive is corrupted, re-request the export and verify checksums immediately before deleting the corrupted copy.
  • When multiple exports fail, check network stability, firewall rules and proxy interruptions. Schedule exports during windows with stable connectivity and reasonable bandwidth limits.

Decision guide: when to export vs relying on the provider

  • Export if data recovery speed or retention needs are stricter than the provider’s default policies, or if you require independent control for legal or business continuity reasons.
  • Rely on provider snapshots for short-term recovery if SLA and retention match your needs, but still keep exports for long-term archival and separation from provider-side incidents.

Including SaaS and web-app exports in your 3-2-1 program adds operational steps, but it’s manageable with clear priorities, automated exports where possible, documented manual processes, and regular verification. For Windows-centric environments, combine these exported copies with your regular workstation and image backups to create a practical, testable 3-2-1 plan that matches your business risk profile.