Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Priority Cleanup de Microsoft Purview: borrar por encima de la retención en Microsoft 365
9 min read

Deleting above retention: three approvals in Exchange, one in SharePoint

Microsoft Purview Priority Cleanup deletes Microsoft 365 content by overriding retention policies, labels and eDiscovery holds, and the documentation says what it deletes cannot be restored by users, by admins, or by Microsoft. Mailboxes always demand three approvals; SharePoint and OneDrive, one — and none from the retention owner. What stops it, what to switch off beforehand, and what it asks of your backup.

Mostrador de pedidos de un almacén con el monitor apagado apartado, una libreta con los pedidos apuntados a mano, albaranes en un pincho y un teléfono descolgado
8 min read

The backup was safe. And it had spent 47 hours inside the same outage

A hosting provider's official status page said two things on the same day: \"there is no risk of data loss\" and \"it is not possible to access backups or migrate affected services to another node\". Both were true, and together they describe the design flaw almost nobody has in their plan: a perfect RPO with an RTO that has no number. We rebuild the clock from the provider's own status page and propose the figure missing from almost every plan: the hour at which you stop waiting.

Rincón de oficina con una papelera metálica desbordada de papel y una destructora con el depósito lleno
9 min read

Recoverable Items: 14 days, 30 GB and the day the mailbox can no longer delete

The folder that saves you when someone empties the deleted items does not show up in Outlook, keeps things for 14 days by default and holds 30 GB. Put the mailbox on hold and the ceiling rises to 100 GB — in exchange for never draining again: things only go in. And on the day it hits that ceiling, per Microsoft's own documentation, the user cannot delete, versions stop being kept and audit entries stop being written. How to measure your headroom with two commands, how to open the drain that ships disconnected, and why a folder deleted with Shift+Delete does not come back even under litigation hold.

Sala de archivo con estanterías metálicas llenas de cajas de cartón y una caja sacada a medias del estante
8 min read

Microsoft 365 Archive is coming to retention policies: compliance up, availability down

This autumn, a Purview retention policy will be able to move SharePoint files into the cold tier (roadmap 561208: preview in September, GA in October). Microsoft promises cost, compliance and search; its own documentation adds that archived content is "no longer directly accessible to anyone" and lists the apps that break: Word and PowerPoint online, the mobile apps, the macOS sync client and Office builds not updated since March. A reactivated file cannot be archived again for 120 days.

Servidor de almacenamiento de 4U extraído sobre sus guías en una sala de servidores, con la tapa quitada y las filas de discos a la vista
9 min read

Proxmox's "protected" flag is not a lock, it's a latch

The Pay2Key ransomware shuts down the guests on a Proxmox cluster and deletes the backups using Proxmox's own API: first a <code>--protected 0</code>, then the delete. We read the pve-storage source to see why it works, and the answer is uncomfortable: clearing the latch never costs one privilege more than deleting the backup. What does raise a real boundary, and why it costs nothing.

Caja fuerte pequeña de oficina abierta sobre una repisa, con dos sobres, un juego de llaves y una memoria USB dentro
8 min read

Cloning the repository is not a GitLab backup

On 17 August GitLab shipped four out-of-band releases for a flaw that lets an unauthenticated user modify or delete public projects. The usual answer — "we have the code cloned everywhere" — is true, and it is the part you are least likely to lose. What a clone actually carries, what lives only on the server, why the secrets file is not inside the backup, and why the June fix, the one with no CVE, explains the problem better.

Estante metálico de una sala técnica con una fila de cartuchos de cinta en sus cajas y una unidad de cinta montada en rack
9 min read

The Microsoft 365 backup that never leaves Microsoft

Microsoft 365 Backup restores a SharePoint site in under twenty minutes, costs $0.15 per protected GB per month and keeps a year of restore points. Its own documentation also says the data never crosses the Microsoft 365 trust boundary, that the storage is append-only rather than immutable, and that deleting the backups is not blocked. Which scenario that covers, which it does not, and the two new dependencies that appear the day you switch it on.

Cuadro eléctrico con filas de interruptores automáticos: apagar cosas una a una antes de que pase lo importante
8 min read

DeadLock does not break your antivirus: it stops it like any other service

On 10 August Microsoft published its breakdown of the DeadLock encryptor. The interesting part is not the cryptography: it is the list of things it switches off before encrypting anything. Defender stopped like a service, shadow copies gone, domain controller services halted and — this is the one almost nobody looks at — event log channels not cleared but disabled in the registry.

Panel de salidas de una estación con horarios anunciados: el papel promete tiempos y el hierro tarda lo que tarda

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3122
min read

RTO and RPO without the fluff: two numbers signed but never calculated

Almost every continuity plan carries an RPO and an RTO written with great confidence and calculated with none. What those two numbers actually promise, why your real RPO is the one of your last verified backup, the four clocks inside an RTO, and the arithmetic that dismantles a "four hours" sitting on a 1 Gbps link.

Fichero de archivo de madera con un cajón abierto lleno de tarjetas catalogadas: dónde vive de verdad cada documento y quién puede abrir el cajón

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3122
min read

That recording lives in the OneDrive of someone who no longer works here

At the end of September, Microsoft moves whiteboards created in Teams channels out of the creator's OneDrive and into the channel's SharePoint site. It is a small change that concedes a large problem: much of a company's collective work lives inside one individual's personal account. Where each recording actually lands, why the deletion clock starts the day you delete the account rather than the day the person leaves, and why leaving the account blocked "just in case" is not the plan you think it is.

Primer plano de papel triturado con restos de texto: el recall en la nube borra el mensaje del buzón del destinatario, y ahora podrá ordenarlo otra empresa
10 min read

Cross-tenant recall: Exchange Online lets another company delete mail from your mailboxes

In mid-August Microsoft starts rolling out cross-tenant message recall in Exchange Online (MC1423106). It ships switched off, and you do not turn it on to recover your own emails: you turn it on so senders in another tenant can delete messages already delivered to your people's mailboxes. What cloud recall does today (hard delete, read messages included, retrying for up to 24 hours), why the allow list looks far too much like the list of domains invoice fraud uses, what actually protects you (retention, not the checkbox), and the logging gap almost nobody has read.

Escalera de evacuación atornillada a la fachada del edificio del que tiene que sacarte: la copia que depende de lo que protege
8 min read

Your backup server sits inside the domain it has to restore

In June, Veeam fixed a 9.4-out-of-10 flaw that let "an authenticated domain user" run code on the backup server. According to third-party technical analysis, on a workgroup server that flaw never came into existence. The difference is not in the code: it is in who your backup server asks whether you can be trusted. What it actually checks, why this is the sixth flaw with the same description in little over a year, the circular dependency nobody draws in the recovery plan, what taking the server out of the domain really costs, and the cases where we would not do it.

La nueva retención por último acceso de Microsoft Purview borra ficheros de SharePoint y OneDrive y deja 93 días de papelera como único margen
7 min read

What nobody opens gets deleted: Purview, last accessed, and the 93 days to notice

By mid-August 2026 Microsoft finishes rolling out a Purview retention rule that deletes SharePoint and OneDrive files nobody has opened for a given period, justified on the grounds that Copilot will answer better. It deletes nothing on its own: somebody has to configure it. But it is the first deletion trigger that measures not a property of the document but the absence of human activity, and the file nobody opens in three years may well be the one you need in year four. What is actually shipping, the 93 recycle-bin days that are your only margin, why version history will not save you, and what we would do before touching that button.

Informe de ransomware 2026: 1,7 millones de dólares de coste medio de recuperación por incidente
7 min read

Restoring is not recovering: two in three recover from backup and nearly half still pay

Sophos's annual ransomware report (2,158 IT leaders across 17 countries, Spain included) brings the biggest backup rebound in the series: 66% of victims whose data was encrypted recovered from backup, twelve points above the 54% of 2025. At the same time 48% paid, and the average cost of recovering rose 11% to $1.7 million with the ransom excluded. Why the two numbers do not contradict each other, the note on method about the two medians almost nobody is reading correctly, what is inside that bill, and the five things worth timing before the bad day.

Romania's land registry
Wiped; saved by the out-of-reach copy
8 min read

Romania's land registry was wiped, backups included. It was saved by the copy the attacker couldn't touch

On July 14 an attacker got into Romania's ANCPI with valid credentials, failed to extort the agency, and wiped the land registry database plus every backup within reach. A week with no property sales or mortgages nationwide. The difference between incident and catastrophe was one copy beyond his reach.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN