If a ransomware restore has already finished but recent work is still absent, do not immediately run it again. First establish whether the remaining problem is deleted content, an unsuitable historical version, or continuing damage from a device or account that has not been secured.
Check whether the environment is stable
Ask the incident-response owner whether affected devices and access paths have been contained and remediated. If restored documents become encrypted again, stop treating this as a date-selection problem. Record the new activity and escalate it. Microsoft’s recovery guidance requires device cleanup before file restoration.
Keep suspect files out of the ordinary working area. Security assessment and content comparison should take place in an approved recovery environment. Do not resume synchronization from an unreviewed laptop to recover one apparently newer document.
Classify each remaining gap
Use one row per document in the recovery record: original URL, current condition, desired edit, candidate source, reviewer and outcome. This avoids repeating a broad operation because a handful of unrelated files have different problems.
- If a document is absent, check deleted items in its owning OneDrive or SharePoint site, not just the current user’s storage.
- If it exists but lacks a recent revision, compare available versions. A version newer than the chosen restore point is only a candidate, not automatically safe.
- If the cloud record has no useful candidate, ask IT about approved backups and preserved device copies.
- If the location is a Teams or SharePoint library, involve that site’s administrator. A user’s OneDrive recovery does not cover every file they can access.
Separate recent work from a clean baseline
Suppose a report contains Monday’s safe figures but Tuesday’s final commentary is missing. The required outcome may be a reviewed copy that combines the clean figures with separately recovered commentary. Reverting the whole drive again is not a content-merge operation.
Retain the candidate sources and identify which portions were accepted. Where data must be reconstructed, label that outcome honestly instead of recording it as an exact recovery of the original file. Have the business owner approve any uncertainty.
Know when a second rollback is justified
A second rollback needs evidence that the first selected the wrong activity boundary, a documented impact assessment and an independent copy of already recovered work. Follow the official restore workflow; do not choose an earlier day merely because the first attempt was incomplete.
For unresolved items, give support the relevant URLs, operation times, errors and validation results. Do not reduce version history, empty recycle bins or rely on an invented local “Sync conflicts” folder as part of recovery. End with a list of restored, reconstructed and still-missing documents so that technical completion does not hide a business-data gap.