News
Self-hosted vs. SaaS backup: what you give up and gain
Duplicati now runs Microsoft 365 and Google Workspace backup two ways: on your own machine with a key only you hold, or fully managed in the Console with nothing to operate. Here's what each model trades away, and how to pick per tenant.
Until this month, backing up Microsoft 365 or Google Workspace with Duplicati meant running Duplicati yourself. You registered an app in your tenant, picked a machine or container to run the job, chose a storage destination, and kept the whole thing healthy. That is still an option, and for many teams it is the right one.
With the new fully managed Microsoft 365 and Google Workspace backup in the Duplicati Console, there is now a second option: you connect your tenant, buy seats, and Duplicati runs the backup for you. No machine, no scheduler, no storage account to set up.
Offering both puts us in an unusual position. Most vendors sell one model and argue that the other is wrong. We think the honest answer is that each model trades something away, and the right choice depends on what you can afford to give up. This article lays out those trades as plainly as we can.
What self-hosting gives you
You hold the encryption key. In a self-hosted Duplicati backup, data is encrypted on the machine running the job, with a passphrase only you know. Nobody at Duplicati, and nobody at your storage provider, can read it. If your compliance regime asks "who can decrypt this data?", the answer is a short list you control.
You decide where the data lives. Back up to an on-prem NAS, a private S3 cluster, Backblaze, Azure, or any of the destinations Duplicati supports. If your customers or regulators require data to stay in a specific country, or off the public cloud entirely, self-hosting is the only model that can promise that outright.
You pay for infrastructure, not seats. A self-hosted M365 or Workspace backup runs under a standard Duplicati license at $0.50 per user per month, and storage is whatever your provider charges. If you already own storage or buy it in bulk, the marginal cost of adding tenants is small.
Nothing about the setup is a black box. You can inspect the backup job, the retention rules, the logs, and the remote files. If Duplicati Inc disappeared tomorrow, your backups would still be restorable with the open-source client.
What self-hosting costs you
Someone has to run it. A cloud-to-cloud backup still needs a place to execute. That means a machine or container that is patched, has network access, and is not switched off on Friday evening. For a homelab this is fun. For an MSP with forty tenants it is a line item.
Tenant setup is the same either way. Both models need an app registration or service account with the right scopes and admin consent in each tenant, and you configure that yourself (Microsoft 365, Google Workspace). The only difference is where you hand the credentials: to your own Duplicati instance, or to the Console. So this is not a cost of self-hosting specifically; it is the entry fee for cloud-to-cloud backup in general.
You are the monitoring. If the job stops running, the only person who notices is you, and only if you set up reporting or connected the machine to the Console. Silent backup failure is the most common way a backup fails you when you finally need it.
Restores are a drill you have to run. Cross-tenant restores, mailbox restores to a different user, and point-in-time recovery all work, but they work because someone practised them. Self-hosting puts that practice on your calendar, not ours.
None of these are reasons not to self-host. They are the work you take on in exchange for the control above.
What managed backup gives you
Nothing to operate. With managed Microsoft 365 and Google Workspace backup, the Console runs the job. There is no machine to keep alive, no scheduler, no container image to update. When Microsoft or Google changes an API, we update the runner; you do not.
Setup stops at the tenant. You still register the app in Microsoft 365 or Google Workspace and hand the credentials to the Console, exactly as you would for a self-hosted job. But that is where the setup ends: no machine to prepare, no destination to configure, no job to schedule.
Storage is included. Each seat comes with 100 GB of Duplicati cloud storage, so there is no separate storage account to provision or bill for. Pricing is a flat per-user amount, which makes it simple to pass through to clients. If you prefer, you can still point the managed backup at your own destination.
Monitoring is already there. Managed jobs report into the same Console you use for machine backups, so alerting, reporting and delegated tenant access apply automatically.
Restores work the same way you are used to. Same-tenant and cross-tenant restores are available from the Console, including restoring a departed user's mailbox or Drive into a different account.
What managed backup asks you to give up
This is the part most SaaS backup vendors leave out, so we will be specific.
The encryption key lives with us. A managed job has no machine of yours to hold the passphrase, so the Console stores it. Data is still encrypted before it reaches storage, and our storage provider never sees a key. But "Duplicati can decrypt this in principle" is a different answer than "nobody but us can", and for some compliance regimes that difference is decisive. We are being upfront about it rather than hiding it in a whitepaper.
You trust our operations. The runner executes in our cloud. You are trusting that we patch it, that we handle the tenant credentials you gave us carefully, and that we handle incidents well. We publish what we can about how the Console is built, but it is still trust in a vendor rather than in your own team.
Data location is ours by default. Duplicati cloud storage is the default destination. If you need the backup to land in a specific region or on your own hardware, you can switch to your own destination, but then you are back to provisioning storage, which erodes some of the convenience.
Recurring cost per seat. Managed backup is priced per user per month. For a tenant with hundreds of users and modest data, self-hosting on storage you already own will usually be cheaper. Convenience has a price, and here it is a visible one.
A dependency on Duplicati as a service. With self-hosting, the open-source client outlives any vendor. With managed backup, the Console holds the key, so you depend on it more. There is a partial escape hatch: you can generate a restore-only key from the Console and use it with the open-source client to restore without the managed runner. That still requires the Console to be reachable and the storage to be paid for, so it protects you from a broken runner or a change of heart about the service, not from Duplicati disappearing. If the latter is the risk you care about, point the managed backup at your own destination.
Side by side
Self-hosted Duplicati | Managed backup in the Console | |
|---|---|---|
Who runs the job | You, on your machine or container | Duplicati, in our cloud |
Encryption key | Held only by you | Stored in the Console |
Storage destination | Any supported destination, your choice | Duplicati cloud storage by default; own destination optional |
Storage included | No, you bring your own | 100 GB per seat |
Tenant setup | App registration per tenant; credentials go to your Duplicati instance | App registration per tenant; credentials go to the Console |
API changes | You update the client | We update the runner |
Monitoring | Configure reporting or connect to Console | Built in |
Restores | Same-tenant and cross-tenant, from the client | Same-tenant and cross-tenant, from the Console |
Pricing | Per-user license plus your storage cost | Flat per user per month |
Works if Duplicati Inc is gone | Yes, open-source client | Restore-only key works with the open-source client while the Console is up and storage is paid; otherwise only for backups on your own destination |
How to decide
Four questions settle most cases.
Can a vendor be allowed to hold the decryption key? If your contracts, regulator or own policy say no, self-host. This is the one question that cannot be negotiated with convenience.
Does the data have to stay in a specific place? Sovereignty requirements point to self-hosting, or to managed backup with your own destination if you accept the key trade-off.
Who will notice when a backup stops? If the honest answer is "probably nobody for a while", managed backup is safer than a self-hosted job nobody watches.
How many tenants, and how much data per user? Many tenants with light data favour managed pricing. Few tenants with heavy data favour bringing your own storage.
In practice this sorts into a few familiar profiles:
Regulated or sovereignty-bound organisations self-host and keep the key.
MSPs onboarding many small clients run managed backup for speed and predictable per-seat billing, and self-host the few clients with special requirements.
Small businesses without an IT function run managed backup, because the alternative is usually no backup at all.
Homelabs and technical teams self-host, because they enjoy it and already own storage.
Mixing is allowed. The Console manages both kinds of backup in one place, so choosing per tenant rather than per company is a reasonable default.
Why Duplicati offers both
We built Duplicati around the idea that you should be able to back up anything to anywhere with a key only you hold. That principle is not going away; self-hosted backup remains the core of the product and the reason most people found us.
Managed Microsoft 365 and Google Workspace backup exists because the most common reason a SaaS tenant is not backed up is not that someone chose the wrong tool. It is that nobody got around to running one. Removing the operational work removes that failure mode, and we would rather offer a model with a stated trade-off than watch tenants go unprotected.
So the choice is yours, per tenant, and you can change your mind later. Both models are managed from the same Console, both encrypt before data leaves the source, and both restore the same way.
Try it: start a free trial of the Duplicati Console and connect a Microsoft 365 or Google Workspace tenant. Or read how self-hosted cloud-to-cloud backup works for Microsoft 365 and Google Workspace.



