04 / Knowledge base
What Microsoft 365 does not back up
9 min read
“It's in the cloud” comes up in conversations about backups more often than anything else, and it usually ends them. Behind it sits a reasonable instinct: if the mail and the files no longer live on a server in the hallway cupboard, then somebody bigger, better equipped and staffed through the night is looking after them. The first half of that instinct is true. The second is a misunderstanding that costs companies data — quietly, and usually late.
Microsoft hides none of this — it calls the arrangement the shared responsibility model and spells it out in its documentation. The catch is that nobody reads that documentation while buying licences, and a salesperson rarely opens with the line that the data inside the service is the customer's responsibility. The result is that in many companies of five to a hundred people, the only thing protecting three years of correspondence is that nobody has deleted it yet.
01
What Microsoft guarantees, and what it does not
Your contract with Microsoft is about the service: that the servers run, that the data centres have backup power, that data is replicated across several locations, and that when a disk fails nobody in your company notices. That part is honoured to a standard no thirty-person business could reach on its own, and it is exactly what paying for cloud buys you. Hardware failure has stopped being your problem.
What sits inside the service — the mail, the files, the Teams conversations, the accounts and their permissions — remains your data and your responsibility. Replication changes nothing about that, because redundancy is not backup: replication copies a deletion every bit as faithfully as it copies a document. A deletion in OneDrive reaches every replica — none of them is an earlier version of the file, so there is nothing to go back to beyond whatever the recycle bin catches. Redundancy protects against infrastructure failure. It does not protect against a person, against malware, or against a policy someone configured badly.
Google Workspace works the same way. The bins and settings have different names, the admin console looks different, and the split of responsibility is identical — the provider answers for the service, the company for what it keeps inside it. So if you are reading this on Workspace rather than Microsoft 365, swap the names and the argument holds.
02
The recycle bin is not a backup, it is a window
Microsoft 365 has recovery mechanisms built in, and they genuinely do help. A deleted message lands in deleted items, a file in the recycle bin, and a document saved after a bad edit can be rolled back to an earlier version. There is also a second-stage bin an administrator can pull things out of after the first one has been emptied. All of it is designed around one specific scenario: a mistake noticed quickly.
Outside that scenario they run out fast. The window is finite, measured in days and weeks rather than years, configurable by an administrator, and almost always shorter than the person relying on it assumes. A gap caught at the quarterly close — a folder of correspondence that stopped receiving anything in June, noticed in October — is inside that window only if somebody lengthened it in your tenant first. The bin also protects only against a mistake, never against a decision: whatever somebody emptied deliberately disappears just as quickly.
We deliberately publish no day counts here, and we would advise against taking them from any article, this one included. They depend on the licence plan, on your tenant's configuration and on policies somebody once set or changed, and the vendor is free to revise them. The only value that matters to your company is the one configured in your tenant today — something to be read out of the admin console rather than taken on faith.
Version history and both recycle bins live in the same tenant as the data. A compromised account with administrator rights, or a retention policy set wrongly, reaches all of them at once. That is why a copy held outside the tenant is not “more of the same” — it is a different kind of protection.
03
The four ways this data actually disappears
Losing data in the cloud rarely looks like an outage. There is no alarm, no error message and no call from the provider — there is the absence of something nobody has looked for yet. Four patterns cover practically everything we meet in companies of this size.
- Somebody deletes a mail folder or a OneDrive directory and notices months later, usually at a period close or when a client asks about old correspondence.
- An employee leaves, the licence is removed because why pay for an unused account — and from that moment a clock is running on a mailbox nobody has been through yet.
- Ransomware encrypts files on a workstation and the sync client dutifully uploads the encrypted versions, because to the sync client it is an ordinary file change.
- A misconfigured retention or sharing policy quietly removes data or exposes it more widely than anyone intended, and keeps doing so until somebody notices.
What all four have in common is that every one of them is authorised. Nothing broke on Microsoft's side — the service did what an account with the right permissions asked it to do. Which is why infrastructure redundancy is no help here: it worked perfectly throughout.
04
The leaver — the most common real loss
Of the four, a small company meets the second most often, and not because it is the most dramatic — because it looks like tidying up. Somebody left, the licence costs money every month, so whoever runs the office does the sensible thing and releases what there is no reason to pay for. Nobody thinks of a mailbox as the company archive, yet for a salesperson or a project manager it is the only place the arrangements with clients were ever written down, including the ones that never made it into a contract.
The trap is that removing a licence is not the same as keeping the data. The exact behaviour depends on the plan and the tenant configuration, so it is not worth guessing; the safe assumption is that releasing a licence starts a clock rather than freezing the mailbox. By the time anyone reaches for that correspondence — a dispute, a complaint, a question from an authority months later — the clock may long since have run out, and that is the moment you find out.
A correct offboarding is two separate jobs done at different speeds. The first is immediate and is about security: on the last day you sign the account out of every session, change the password, revoke the second factor and remove access to the systems the person used. The second is a decision about data: what happens to the mailbox and the files, who takes them over, and whether they are inside a backup before anything is released. Only then does the licence go back into the pool. The order is the whole point — the reverse order costs you data.
05
What a Microsoft 365 backup has to have
Between “we have backups” and actually having one lie five conditions. The first four come with the tool and can be ticked off when the supplier's contract is signed. The fifth is of a different kind — and it is the one that decides whether the other four mean anything.
That fifth one is a restore actually performed. Buying the tool is a purchasing decision; verifying it is a process: at a set interval somebody has to pick a mailbox or a library, genuinely restore something from it, and confirm the file opens and contains what it should. In our ongoing support, backup oversight and restore tests are part of the scope written into the agreement, because the restore is what turns an expense into a protection.
- A separate copy outside the tenant — with another provider or on your own NAS in the office — because a copy kept where the data lives shares whatever happens to it.
- A retention period the company chooses rather than inherits from a default: if you need documents from two years ago, the copy has to reach two years back.
- Point-in-time restore — the ability to say “we want this library as it was on Friday morning”, not only to pull back one file at a time.
- Coverage of everything the company actually works in: mail, OneDrive, SharePoint and Teams, because the files and decisions in channels are today's project documentation.
- A restore that has actually been performed, with the date and result written down somewhere other than in someone's head, because until something has come back you have an assumption, not a backup.
06
How much to keep and for how long is a business decision
Separately from accidents there is obligation. Some documents have to be at hand years later — for an inspection, a dispute, a complaint, or a client asking about a contract from several seasons ago. How long, and which ones exactly, is a question for your accountant and your lawyer, not for an IT provider; our job is to make sure the answer can be implemented. No cloud recycle bin reaches that far, and none was built to.
In practice it is worth separating two things that blur into one in conversation. Everyday recovery should be fast and reach back weeks — it is what saves you after a mistake and after ransomware. An archive reaches back years, is rarely touched and can sit on cheaper storage. A company that treats them as one subject either overpays to keep everything for a long time or discovers after three years that it kept too little. It is also fair to say that with a six-person team a narrower arrangement can be the right one — mail and a single SharePoint library rather than everything — provided it is a deliberate decision rather than an accident.
07
Two questions worth asking this week
Nothing has to be bought or changed today. Two answers are enough to know where the company stands. First: what the retention in your tenant is actually set to — not in the plan, not in the brochure, but in the console, today. Second: whether anyone has ever restored anything from it.
The first question is a job for an administrator — the answer is read straight out of the console. The second is a question for whoever handles your IT, and it has exactly one valid form of answer: a date, the name of a file or mailbox, and whether it worked. “We definitely have backups” is not an answer — it is the memory of somebody's assumption.
If neither answer exists, it does not yet mean the company is at risk. It means the company does not know — which is a different thing from being safe. The difference tends to surface in the worst possible week.