Does Microsoft 365 Back Up Your Data? What Business Owners Need to Know
This is one of the most common misunderstandings in small business technology. Microsoft 365 provides redundancy and resilience — your data is stored across multiple datacenters and protected against hardware failure. That is not the same as backup. There are real scenarios where Microsoft 365 data is gone, and Microsoft cannot recover it.
What Microsoft actually provides
Microsoft 365 uses geo-redundant storage. Your data exists in multiple locations simultaneously. If one datacenter has a problem, your data is still accessible from another. This protects against infrastructure failure. Microsoft's service level agreement covers this.
Microsoft also provides soft delete functionality. When you delete an email, it goes to the Deleted Items folder. When you empty that, it goes to the Recoverable Items folder for a default period (around 30 days for most plans). When that expires, it is gone. When you delete a file from SharePoint or OneDrive, it goes to the recycle bin for 93 days. After that, it is gone.
This is not backup. This is a recovery window. There is a meaningful difference.
What is not protected
| Scenario | Microsoft protects you? | Notes |
|---|---|---|
| Datacenter hardware failure | ✓ | Geo-redundant storage handles this |
| Microsoft service outage | Partial | Data intact; access temporarily unavailable |
| Accidental deletion within retention window | ✓ | Recoverable from recycle bin or soft delete |
| Accidental deletion beyond retention period | — | Data is permanently deleted |
| Ransomware encryption of SharePoint/OneDrive | Partial | Version history helps if caught early; may not cover all scenarios |
| Deliberate malicious deletion by insider | — | If retention period has passed, data is gone |
| Account deletion after offboarding | — | Mailbox and OneDrive data deleted after a grace period |
| Mass deletion by compromised admin account | — | Depends on timing and what was affected |
| Retention policy expiry | — | Data purged per policy; intended but sometimes unintended |
The scenarios that create real risk
Ransomware is the scenario most organisations think of first. The good news is that SharePoint and OneDrive do maintain version history, and Microsoft has introduced some restoration capabilities for ransomware scenarios. The bad news is that these capabilities have limits — particularly for large-scale or sophisticated attacks — and relying solely on version history is not a backup strategy.
Employee departure is more common and less dramatic. When you remove a user account, Microsoft gives you a grace period to export their mailbox and OneDrive data. Many organisations do not do this. After the grace period, the data is deleted. If six months later someone asks for an email from that person's account, it is gone.
Accidental deletion is the most frequent. A staff member deletes a shared folder. A misconfigured retention policy purges a mailbox. A SharePoint site is removed by someone with admin access. These things happen, and if the retention window has passed, Microsoft has nothing to restore.
What retention policies actually do
Microsoft 365 retention policies (configured in Microsoft Purview) can preserve content for a defined period even if a user deletes it. This is a compliance tool, not a backup solution. It addresses specific retention requirements (you need to keep email for seven years) rather than the operational need to restore a specific file to a specific point in time.
Retention policies also do not help you restore something to a specific version, recover a file that was overwritten, or browse previous states of a SharePoint site. They keep a copy of content for the defined period, but they do not give you backup software's restore-to-point-in-time capability.
The recycle bin is not backup. Retention policies are not backup. Version history is not backup. Backup means you have a recoverable copy of your data at a known point in time, independent of whether Microsoft's service retains it.
What to do about it
There are broadly two approaches. The first is a third-party backup solution specifically designed for Microsoft 365 — products like Veeam, Acronis, or Druva take regular snapshots of your Exchange, SharePoint, OneDrive and Teams data and store them independently. This gives you genuine restore capability.
The second approach is ensuring that Microsoft's built-in retention and recovery tools are properly configured for your situation, combined with documented offboarding procedures, admin access controls, and an understanding of what your actual recovery requirements are.
Which approach is right depends on your data sensitivity, compliance requirements, and risk tolerance. What is not appropriate is assuming Microsoft is handling backup and doing nothing.
Next step
Managed Cloud
Managed Cloud includes ongoing review of your Microsoft 365 environment, including data governance, retention policy configuration, offboarding procedures and proactive identification of gaps like the ones described here.
Learn more