Object Lock (Immutability)
This chapter describes Object Lock (Immutability) support for Microsoft 365 / Google Workspace Backup. For information on how Object Lock (Immutability) is supported for backup plans in the new backup format with GFS, refer to the following article.
This chapter covers the following topics:
- About Object Lock (Immutability)
- Retention Modes for Immutable Data
- Grant 'Manage Object Lock (Immutability)' Permission
- Allow Default Object Lock for Storage Account
- Edit Default Object Lock Settings for Storage Account
- Disable Default Object Lock for Storage Account
- Allow Object Lock for GFS backups for Storage Account
- Disable Object Lock for GFS backups for Storage Account
- Manage Object Lock for GFS backups Using Retention Policies
About Object Lock (Immutability)
Object Lock is a feature that locks backup datasets for a period specified by the default or a custom retention policy. If Object Lock is allowed for the backup storage, all backups with a configured retention policy that are created in this backup storage become immutable for the retention period. Within this period, backup data is kept unmodified.
The Object Lock feature supports the following feature types:
- Default Object Lock (New)
- Object Lock for GFS backups (formerly Object Lock (Immutability)). This feature is not applicable to backups without a configured retention policy.
In the selected backup destination for Microsoft 365 / Google Workspace, only one of these feature types should be enabled.
Default Object Lock (New)
Default Object Lock is an alternative immutability type in which all backup data written to the backup destination is automatically locked.
- Configured on the cloud storage provider side
- Applied automatically to all backups using the destination
The Default Object Lock feature does not require a configured default or custom retention policy. If a retention policy is configured, ensure that the retention period is longer than the default Object Lock period.
Object Lock for GFS Backups
Object Lock for GFS backups (formerly Object Lock (Immutability)) is applied only to backup data created using Microsoft 365/Google Workspace Backup and is not applicable to backups without a configured retention policy.
- Configured in Managed Backup
- Requires the Manage Object Lock (Immutability) permission for administrators.
If storage with the Object Lock feature enabled is selected for Microsoft 365 / Google Workspace Backup, you will see the Object Lock icon on the main menu of the Service Dashboard.

Support for the Object Lock for GFS backups feature depends on the assigned retention policy. If Object Lock for GFS backups is applied along with retention policy settings, backups that are subject to the retention policy become immutable for the period specified by the retention policy. Refer to the table below for details on how it works.
| Object Lock on Backup Destination | Default Retention Policy | Custom Retention Policy | RESULT | Comment |
|---|---|---|---|---|
| ✔️ | ✔️ | ✔️ | Backup locked | Unable to delete backup data until the period set by the custom retention policy expires |
| ✔️ | ✔️ | ❌ | Backup locked | Unable to delete backup data until the period set by the default retention policy expires |
| ✔️ | ❌ | ✔️ | Backup locked | Unable to delete backup data until the period set by the custom retention policy expires |
| ✔️ | ❌ | ❌ | Backup NOT locked | Backup data can be deleted |
| ❌ | ✔️ | ✔️ | Backup NOT locked | Backup data can be deleted |
| Top |
Retention Modes for Immutable Data
Generally, two object lock retention modes are supported for immutable storage:
Governance mode (default; all storage types work in this mode). In Governance mode, protected objects in backup storage are locked (users cannot overwrite or delete an object version or alter its lock settings using the Management Console or Backup Agent). These objects can only be deleted using cloud storage provider tools. By design, when you create a destination bucket using the Management Console, the Governance mode is used for all destination buckets with Immutability enabled.
Compliance mode. In Compliance mode, protected objects in backup storage are locked completely (users cannot overwrite or delete an object version or alter its lock settings using the Management Console or Backup Agent). These objects cannot be deleted until their retention period defined in the retention policy settings ends.
Neither the Management Console nor Backup Agent provides an option to switch the object lock retention mode for existing destination buckets. If you need to use Compliance mode, contact MSP360 support.
The Object Lock feature should be configured carefully, especially in Compliance Mode. When enabled, backup data becomes immutable and cannot be deleted or modified until the retention period specified by the policy expires. This restriction applies even to administrators, and the only way to remove such data is by terminating the entire storage account.
| Top |
Grant 'Manage Object Lock (Immutability)' Permission
To delegate Object Lock management to administrators:
- Open the Management Console.
- Go to Organization > Administrators.
- Click Edit for the administrator account you are planning to use for backup storage management.
- Open the Permissions tab.
- Enable Manage Object Lock (Immutability).

- Click Save.
| Top |
Allow Default Object Lock for Storage Account
Ensure that Object Lock is enabled on the storage.
To allow Default Object Lock, proceed as follows:
- Open the Management Console.
- On Storage Accounts, select the account for which you want to allow Default Object Lock, or create a new storage account.
- Expand the actions, then select View Backup Destinations.
- Click Add Destination Bucket to create a new backup destination for immutable backups.
- In the Destination Bucket property box, fill in the required data (create or select an existing bucket), then click Set Default Object Lock.

Do not use Default Object Lock and Object Lock for GFS backups on the same storage.
- Confirm the action.
Wasabi: Buckets with Object Lock enabled must also have Versioning enabled.
| Top |
Edit Default Object Lock Settings for Storage Account
If the Object Lock period is changed on the storage side:
If Object Lock settings can be read from the storage, the protection period is populated automatically.
If the settings cannot be read, you will be prompted to provide the protection period settings manually.
To provide the protection period settings manually, proceed as follows:
- Open the Management Console.
- On Backup > Storage Accounts, select the required account.
- Click the storage account name to view a list of backup destinations.
- Click the edit icon at the end of the required backup destination record.

- In the Edit destination dialog, edit the number of days below the Set Default Object Lock checkbox to provide the correct value.

- Click Save.
Disable Default Object Lock for Storage Account
If Object Lock is disabled on the storage side:
- Existing immutable backups remain locked until their retention period expires.
- All newly created backups will not be purged during the Default Object Lock period specified in the Management Console.
In this case, it is recommended to disable Default Object Lock for the storage account in the Management Console. To do this, proceed as follows:
- Open the Management Console.
- On Backup > Storage Accounts, select the required account.
- Click the storage account name to view a list of backup destinations.
- Click the edit icon at the end of the required backup destination record.

- In the Edit destination dialog, clear the Set Default Object Lock checkbox.

- Click Save.
Now all newly created backups will be purged according to the retention policy settings.
| Top |
Allow Object Lock for GFS Backups for Storage Account
Note that Object Lock for GFS backups (formerly Object Lock (Immutability)) should be allowed in the Management Console. Do not use this feature if Object Lock is enabled on your storage destination.
If you need to comply with regulations, maintenance or legal requirements, or anything else that requires an immutable backup dataset, enable this feature for an appropriate storage account. If you do not have any storage destinations with Object Lock for GFS backups allowed, you can create a new destination bucket in the Management Console.
To use the Object Lock for GFS backups feature, the appropriate permission must be granted to the account used for the backup storage connection. For example, for S3 destinations, the GetBucketObjectLockConfiguration permission must be granted.
AWS S3
Ensure that the GetBucketObjectLockConfiguration permission is granted.
To allow Object Lock for GFS backups, proceed as follows:
- Open the Management Console.
- On Storage Accounts, select the account for which you want to allow Object Lock for GFS backups, or create a new storage account.
Note that the 'list versions' permission must be enabled for the storage account.
- Expand the actions, then select View Backup Destinations.
- Click Add Destination Bucket to create a new backup destination for immutable backups.
- In the Destination Bucket property box, fill in the required data (create or select an existing bucket), then select Allow Object Lock for GFS backups.

- Confirm the action.
- Once you are done, proceed to the Microsoft 365 / Google Workspace Dashboard to create retention policies for specific services or exported PST files. The allowed feature is enabled on the specified bucket only and does not affect any backups or exported files. You should create retention policies for every service or exported PST file to apply the Object Lock period to them as described below.
Note that if a bucket has the Allow Object Lock for GFS backups feature enabled, versioning for this bucket is automatically enabled as well.
| Top |
Wasabi
To allow Object Lock for GFS backups for Wasabi, proceed as follows:
- Open the Management Console.
- On Storage Accounts, select the account for which you want to allow Object Lock for GFS backups, or create a new storage account.

Allow Object Lock for GFS backups can only be enabled at the time a bucket is created. Buckets with Object Lock for GFS backups enabled must also have Versioning enabled.
- Expand the actions, then select View Backup Destinations.
- Click Add Destination Bucket to create a new backup destination for immutable backups.
- In the Destination Bucket property box, fill in the required data (create or select an existing bucket), then click Allow Object Lock for GFS backups.

- Confirm the action.
- Once you are done, proceed to the Microsoft 365 / Google Workspace Dashboard to create retention policies for specific services or exported PST files. The allowed Object Lock for GFS backups enables this feature on the specified bucket only and does not apply this feature to any backups or exported files. You should create retention policies for every service or exported PST file to apply the Object Lock period to them as described below.
| Top |
Backblaze B2
To allow Object Lock for GFS backups for Backblaze B2 destinations, proceed as follows:
- Open the Management Console.
- On Storage Accounts, select the Backblaze account for which you want to allow Object Lock for GFS backups, or create a new Backblaze storage account.
- Expand the actions, then select View Backup Destinations. If you have just created a new Backblaze storage account, follow the storage account creation wizard.
- Click Add Destination Bucket to create a new backup destination for immutable backups.
- In the Add Destination Bucket box, select the Create new bucket option, specify the new bucket name, then select the Allow Object Lock for GFS backups checkbox. If you want to use an existing bucket, click ..., then select the required bucket from the list.
Object Lock for GFS backups can only be enabled at the time a bucket is created. Thus, if you select an existing bucket, it must already have Object Lock for GFS backups enabled. For existing buckets with no Object Lock for GFS backups enabled upon creation, there is no way to enable it. You can always check the Object Lock for GFS backups status of existing backup destinations on the 'Backup Destinations' page.

- Confirm the action.
- Once you are done, proceed to the Microsoft 365 / Google Workspace Dashboard to create retention policies for specific services or exported PST files. The allowed Object Lock for GFS backups enables this feature on the specified bucket only and does not apply this feature to any backups or exported files. You should create retention policies for every service or exported PST file to apply the Object Lock period to them as described below.
| Top |
Disable Object Lock for GFS Backups for Storage Account
If you want to stop Object Lock for GFS backup protection:
- Existing immutable backups remain locked until their retention period expires.
- All newly created backups will not be purged during the retention policy specified in the Management Console.
- Open the Management Console.
- On Backup > Storage Accounts, select the required account.
- Click the storage account name to view a list of backup destinations.
- Click the edit icon at the end of the required backup destination record.

- In the Edit destination dialog, clear the Allow Object Lock for GFS backups checkbox.

- Click Save.
Now all newly created backups will be purged according to the retention policy settings.
Manage Object Lock for GFS Backups Using Retention Policies
Note that Object Lock for GFS backups (formerly Object Lock (Immutability)) is not supported for backups without an applied retention policy.
Refer to the following articles for details on how to configure retention policies:
| Top |