Frequently Asked Question

Limiting your Server Quota by Design
Last Updated 25 days ago

You can purchase storage for your private virtual server from 1GB to 5TB, but there are many reasons why keeping it as low as practically possible is strongly preferable — not just for performance, but for security.

Why this matters now

Cloud mailboxes and file stores are one of the most heavily targeted assets in any organisation today. Attackers increasingly don't need to "hack" anything in the traditional sense, they steal or trick their way into a legitimate account, then simply help themselves to whatever is sitting inside it. 

In the past three years there have been several high-profile Microsoft data breaches and over 1,200 vulnerabilities reported, affecting millions of users and organisations. Recent campaigns show this isn't slowing down: one 2026 threat actor group compromised user accounts and then exfiltrated files from organisations' Microsoft 365 storage, including OneDrive and SharePoint, in one case downloading thousands of files in a single action. Separately, a phishing campaign active since December 2025 has been bypassing multi-factor authentication entirely by stealing OAuth tokens after a user completes a legitimate MFA challenge, granting attackers persistent access to Microsoft 365 accounts and data. 

The lesson from every one of these incidents is the same: once an account is compromised, the blast radius is defined by how much is sitting inside it. A compromised mailbox with 500MB in it is an inconvenience. A compromised mailbox === or OneDrive/SharePoint library === with 50GB in it going back a decade is a data breach, a regulatory problem, and potentially a front-page story. Keeping your footprint lean is one of the few controls that directly limits damage after a compromise has already happened, even if every other layer (MFA, conditional access, training) has failed.

Compliance angle

This isn't just best practice — it's directly relevant to the standards many of you are already being assessed against:

ISO 27001 requires organisations to classify and manage information according to its value and sensitivity, and its Annex A controls specifically call for defined data retention and secure disposal practices. An unmanaged, ever-growing mailbox, website or file store with no retention policy is a straightforward audit finding, and a genuine control gap, not just a paperwork issue.

PCI-DSS is even more explicit: Requirement 3 states that cardholder data storage should be kept to a minimum, with retention and disposal policies limiting storage to what's required for legal, regulatory, or business purposes. If card data (or anything resembling it such as names, addresses, DOB, cardholder names etc) is sitting in old emails or an oversized database "just in case," that's a compliance failure waiting to be found, either by an auditor or, worse, by an attacker.

UK GDPR / Data Protection Act adds another layer for anyone holding personal data: the storage limitation principle requires that personal data not be kept longer than necessary for the purpose it was collected for. A compromised mailbox holding ten years of customer correspondence isn't just a bigger breach, it's a bigger breach of data you arguably shouldn't have been holding in the first place, which materially affects any ICO assessment of the incident and legal penalties. 

The practical upshot is the same across all three: minimising and periodically purging your footprint isn't only about performance or containing the blast radius of a compromise, it's evidence, in an audit or after an incident, that you were actively managing risk rather than just accumulating data by default.

Email

For enterprise email, you can allocate the server storage quota to mailboxes as required, but simply allocating massive mailboxes presents challenges to clients, security and retention.

The larger the mailbox, the slower the client will become, this varies between systems but all are affected to some degree, especially mobile devices.

The larger the mailbox, the greater the damage should an account be compromised. A phished or compromised account with years of email in it hands an attacker a ready-made archive of invoices, personal data, contracts and credentials to mine, exactly the pattern seen in recent large-scale Microsoft 365 exfiltration campaigns.

The larger the mailbox, the greater the risk of loss should there be a technical issue, or should someone accidentally delete it, or bulk erase, etc.

You can configure mailboxes to self-delete email older than a set period for any that are non-critical, or optionally purchase a GEN hosted email backup service, which will create a periodic backup of all email, then remove it from the mailboxes, or use your own hosted service to download and purge email via IMAP, or for smaller configurations, a single client on a PC can be used to archive email (by setting up all mailboxes on that machine, and setting up auto-archive).

Whichever you choose, keeping mailboxes between 1GB and 5GB should be the aim, treat this as a security control, not just good housekeeping and justify anything larger with a compelling case. 

Data

Storing large amounts of data on your hosted database(s) presents a clear risk should your front-end system be compromised. As a policy, only store the information required for the daily operation of your solution, archiving or purging everything else. GEN have a dedicated DataLake platform which can be leveraged to offload data, or you can download it periodically using some front-end applications.

Web

The larger the website the slower it will be rendered to visitors, and since images often form the bulk of the storage, optimising these brings with it many advantages. There are tools to do this available both online and in software, or again GEN offer an image refactoring service. Keeping things like ecommerce transactions, user accounts, user activity and similar longer than absolutely required online, also presents a clear risk should the site be compromised. Offload data (pull) daily to a corporate system to keep the risk minimal. 

The bottom line

None of this is about distrusting any particular platform (although there are some you can trust more than others),  it's about accepting that account compromise is now a matter of probability, not possibility, for every organisation. Minimising what's exposed at any one time is the single most effective way to make sure that when, not if, an incident occurs, it's a minor one.

Advice

As a GEN Customer, you are afforded free advice on any of these via the HelpDesk or your Account Manager, so please make use of this anytime you need it.

This website relies on temporary cookies to function, but no personal data is ever stored in the cookies.
OK
Powered by GEN UK CLEAN GREEN ENERGY

Loading ...