Microsoft 365 is not backed up, and Microsoft says so
Microsoft keeps the service running. Your data is your responsibility. What the retention periods actually cover, where they run out, and why a deleted mailbox can be permanently gone in 30 days.
Almost every business we assess believes its Microsoft 365 data is backed up. Almost none of them have a backup.
The confusion is understandable. Microsoft replicates your data across data centres, so it survives hardware failure, fire and flood. That is resilience, and it is excellent. It is not a backup, because it does not protect you from the thing that actually happens: somebody deletes something.
The shared responsibility model
Microsoft documents this openly. It is responsible for the availability of the service, the infrastructure and the uptime. You are responsible for your data, your accounts and your retention requirements.
Put plainly: Microsoft guarantees you can reach your mailbox. It does not guarantee that what you want is still in it.
What retention actually gives you
There are recovery mechanisms in Microsoft 365, and they are useful. They are also short and easy to exhaust.
- Deleted items in Exchange Online are recoverable for 14 days by default, extendable to 30.
- Recoverable items, the second-chance folder behind that, holds for 14 days by default and can be extended to 30.
- SharePoint and OneDrive recycle bins hold for 93 days across both stages, after which the content is gone.
- A deleted user account is recoverable for 30 days. After that, the mailbox and the OneDrive contents are unrecoverable.
- Version history in SharePoint and OneDrive helps with an overwritten file, but not with a deleted library.
Every one of those is a window, not an archive. They are designed for a mistake noticed this week.
Where that leaves you exposed
The departure nobody handled properly
An employee leaves. Their licence gets removed to save cost, the account is deleted a few weeks later, and four months on somebody needs a contract from their mailbox. It is not recoverable. This is the single most common way we see data permanently lost.
Ransomware that syncs
OneDrive and Teams files sync from the desktop. Encrypt the desktop copies and the encrypted versions sync up. Version history can save you if you catch it quickly and the file count is manageable. At scale, across thousands of files, it is a long and painful recovery.
Deletion by someone with access
A departing employee clearing out their own work, or an angry one clearing out someone else's, is a business risk rather than a technical one. Retention windows will not help if the discovery comes months later.
Compliance and disputes
A labour dispute or a POPIA request can need email from two years ago. Retention policies can be configured to hold that, but they have to be configured deliberately, and most tenants we look at have never had them touched.
Retention policies are not backups either
Microsoft 365 retention policies can preserve data for years, and they are worth configuring. They are still not a backup, for two reasons. They preserve rather than restore, so getting data back means eDiscovery searches rather than a restore operation. And they live inside the same tenant, so a compromised administrator account with sufficient privilege can affect them.
What a real backup looks like
- Separate from the tenant. Held somewhere a compromise of your Microsoft 365 cannot reach.
- Covers everything. Exchange, SharePoint, OneDrive and Teams, including chat.
- Long retention. Years, defined by your obligations rather than by a default.
- Point-in-time restore. Recovering a mailbox as it was on a specific date, not just a file.
- Tested. An untested backup is a hope. Restores should be proved on a schedule and the results recorded.
Two questions to ask today
First, if an employee left six months ago and their account was deleted, can you get their email back? Second, has anyone ever performed a test restore and shown you the result?
If either answer is no, the gap is worth closing. We include Microsoft 365 backup with tested restores as part of backup and disaster recovery, and we are happy to look at your tenant and tell you exactly what is and is not currently protected.
