Why Microsoft 365 Data Still Needs Backup

Microsoft 365 is not a backup. Microsoft's own services agreement recommends you regularly back up your content using third-party services, because Microsoft's job is keeping the service available — not preserving your data against deletion, ransomware, malicious insiders, or sync errors. Native retention gives you a short recovery window (14–30 days in most scenarios), and once it lapses, the data is gone permanently. If your business runs on Exchange, OneDrive, SharePoint, or Teams, you need an independent backup of all four.

That surprises a lot of business owners, so let's walk through exactly where the gaps are.

What is the shared responsibility model?

It's the deal you agreed to when you signed up: Microsoft is responsible for the platform — uptime, datacenters, infrastructure, and resilience against their failures. You are responsible for your data — what your users create, delete, overwrite, or lose to an attacker. Microsoft replicates your data across datacenters so a hardware failure doesn't lose it, but replication faithfully copies every mistake: delete a file, and the deletion replicates too.

Think of it like a serviced office building. The landlord keeps the power on, the doors locked at night, and the sprinklers working. But if your bookkeeper shreds a filing cabinet's contents — accidentally or on purpose — the landlord isn't reconstructing your records. Replication is not backup: a backup is an independent, point-in-time copy you can restore from after something bad happens, held somewhere the bad thing can't reach.

Every major cloud vendor works this way, and Microsoft is refreshingly direct about it — the Microsoft Services Agreement states plainly that they recommend regular third-party backup of your content and data.

How long does Microsoft 365 actually keep my data?

Shorter than most people assume. Deleted emails are recoverable for roughly 14–30 days after leaving Deleted Items. Deleted user mailboxes survive 30 days. OneDrive and SharePoint recycle bins hold items for 93 days, with a 30-day whole-library rollback for disasters. All of these are safety nets for recent, noticed mistakes — not archives.

Data Native protection Hard limit
Deleted email (after Deleted Items emptied) Recoverable Items folder 14 days default, 30 days max
Departed employee's mailbox (account deleted) Soft-deleted mailbox retention 30 days, then permanent deletion
OneDrive / SharePoint deleted files Two-stage recycle bin 93 days total, then gone
OneDrive / SharePoint mass corruption Files Restore rollback 30 days back, maximum
File overwrites Version history 500 versions default; versions can be trimmed or purged
Teams chats and channel messages Retention policies (if configured) Compliance tool — no simple restore of a conversation

Two things to notice in that table. First, every window is measured in days, while real-world problems are often discovered in months — an accountant notices missing invoices at quarter-end, a lawsuit demands emails from a year ago, a project resurrects and its SharePoint library was "cleaned up" in the spring. Second, retention policies and litigation hold can preserve data much longer, but they're compliance features: designed to prove what existed, not to put a user's mailbox or a document library back the way it was on a given Tuesday. Restoring from a hold is a slow eDiscovery exercise, not a right-click.

What scenarios won't Microsoft save you from?

The common ones. Accidental deletion discovered too late. A departing employee who wipes their mailbox and OneDrive on the way out. Ransomware that encrypts synced files and outruns or tampers with version history. A compromised admin account used to delete data and the retention policies protecting it. A misconfigured retention or sync policy that quietly purges data you thought was safe.

A few of these deserve elaboration:

  • The malicious insider. An employee who resigns on bad terms has, until you disable their account, full power to purge years of email and files. Some of that purging can exceed native recovery windows before anyone thinks to look.
  • Ransomware targeting cloud data. Attackers know SMBs live in Microsoft 365 now. Encryption events sync to OneDrive/SharePoint; sophisticated attacks use compromised admin credentials to disable protections first. Your backup must live outside the tenant, under separate credentials, precisely so that an attacker who owns your Microsoft 365 admin account still can't touch it. This is the same logic behind every good backup and disaster recovery design: at least one copy the attacker can't reach.
  • The 31st day. Nearly every native protection has a cliff — day 15, day 31, day 94. Independent backups replace cliffs with retention you choose: one year, three years, seven years for regulated industries.
  • Account and licensing churn. Downgrade a license, delete a user, or restructure a Teams site, and data can evaporate on a schedule nobody's watching.

If you can't say with confidence how many of these your current setup survives, that's worth a conversation — book a free IT assessment and we'll check your tenant's actual retention settings and backup coverage in plain English.

What does a proper Microsoft 365 backup look like?

Automated, at least daily, covering Exchange, OneDrive, SharePoint, and Teams, with retention measured in years, granular restore down to a single email or file, and storage independent of your tenant credentials. Those six attributes are the whole checklist — and pricing in the third-party market typically runs a modest $3–$10 per user per month, making this one of the highest-value line items in a small-business IT budget.

A few buying notes from the field:

  • Teams is the one vendors skimp on. Chat and channel data is technically awkward to back up; verify exactly what a product captures rather than trusting a "Teams: ✓" on a datasheet.
  • Test restores, not backups. The only backup metric that matters is a successful restore. A good provider does periodic restore tests as a standing practice.
  • Mind who holds the keys. Backups reachable with the same global admin credentials as the tenant fail the ransomware test. Separate credentials, ideally with MFA and immutability options.
  • Backup complements, doesn't replace, tenant hardening. MFA, conditional access, and sensible retention policies reduce how often you need the backup. A well-configured tenant plus independent backup is the full picture — which is why we treat backup as part of the same conversation as cloud and Microsoft 365 management rather than an afterthought.

Isn't this overkill for a small business?

No — small businesses are precisely who gets hurt, because they have no legal team to fight an eDiscovery fire drill, no spare staff to recreate lost work, and no cushion for the downtime. Industry studies consistently put the cost of downtime for small businesses in the range of $10,000-plus per hour for some sectors, and even conservative estimates of recreating a single lost mailbox run into thousands of dollars of staff time.

Meanwhile the exposure is total: for most companies under 100 employees, Microsoft 365 is the business record — every contract negotiation, client file, and financial document lives there. Paying a few dollars per user per month so that no deletion, departure, attack, or misconfiguration can permanently destroy that record isn't overkill. It's the same reason you lock the office and insure the building. Microsoft keeps the lights on; keeping copies of what's inside is on you.

Frequently asked questions

Doesn't Microsoft already back up my email and files?
Microsoft backs up its infrastructure to keep the service running — that protects against Microsoft's hardware failing, not against your data being deleted, overwritten, or encrypted. Under Microsoft's shared responsibility model, your data is your responsibility. Built-in retention features can help you recover recent deletions, but they have hard time limits and were never designed to be a backup system with independent copies and point-in-time restore.
How long does Microsoft 365 keep deleted emails?
A deleted email sits in the Deleted Items folder until someone empties it, then moves to the Recoverable Items folder for 14 days by default, extendable to a maximum of 30. After that it is gone. If a departing employee purges their mailbox, or a problem isn't noticed for six weeks, native retention will not save you. Litigation hold and retention policies can preserve data longer but are compliance tools, not restore tools.
What happens to a mailbox when an employee leaves and the license is removed?
When you delete a user account, Microsoft retains the mailbox for 30 days by default, after which it is permanently deleted. Many businesses discover this only when they need a former employee's email months later. Workarounds like converting to a shared mailbox or applying litigation hold exist, but they require someone to act before deletion — a third-party backup keeps the data regardless of licensing decisions.
Does OneDrive versioning protect against ransomware?
Only partially. OneDrive and SharePoint keep 500 versions by default, and Microsoft offers a 30-day file restore for OneDrive and SharePoint document libraries, which can roll back a ransomware encryption event — if you catch it within 30 days and the attacker hasn't tampered with versions or deleted files past retention. Modern attacks increasingly target cloud data deliberately. An independent backup with its own credentials and retention removes the time pressure and the single point of failure.
What should a Microsoft 365 backup actually include?
At minimum: Exchange Online mailboxes (including calendars and contacts), OneDrive for Business, SharePoint sites, and Teams data — chats, channel conversations where supported, and the files behind them. Look for automated backups at least daily, retention you control (a year or more, not 30 days), point-in-time restore, granular recovery of single items, and storage independent of your Microsoft 365 tenant credentials so a compromised admin account can't destroy the backups too.
How much does Microsoft 365 backup cost for a small business?
Third-party market pricing for Microsoft 365 backup typically runs about $3 to $10 per user per month depending on the vendor, retention length, and whether it's bundled with managed services. For a 25-person company that's roughly $75 to $250 a month — usually the cheapest line item in the IT budget relative to the risk it covers, since even one unrecoverable mailbox or SharePoint library can cost far more in lost work and legal exposure.

Find out what your IT should be doing for you

Get a free, no-obligation IT assessment — a plain-English report on your security, backups, and support gaps.

Get Your Free IT Assessment