"It's in the cloud, so Microsoft backs it up" is one of the most expensive assumptions in IT. Microsoft protects the service: its datacentres, its infrastructure and its copies of your data for disaster recovery. Getting back a mailbox someone emptied six months ago, or thousands of files encrypted by ransomware, is a different problem, and under Microsoft's own model most of it is yours.
The shared responsibility model
Microsoft splits cloud security into what it owns and what the customer owns. For software-as-a-service such as Microsoft 365, Microsoft is responsible for the physical datacentres, network and hosts. The customer is always responsible for three things: data, devices and accounts. In Microsoft's words: "you own your data and identities. You're responsible for protecting the security of your data and identities."
Microsoft has since launched its own backup product, and its backup FAQ is explicit that this does not change the split. It is simply offering more tools for the customer's side of it.
What you can recover by default
Microsoft 365 does keep deleted items for a while. These are the default windows, and once they pass the data is gone:
| What was deleted | Default recovery window |
|---|---|
| Email items (Recoverable Items) | 14 days, adjustable up to 30 days |
| A whole mailbox (soft-deleted) | 30 days |
| SharePoint and OneDrive files (recycle bins) | 93 days in total, counted from the original deletion |
| SharePoint content after the recycle bin | 14 more days, restorable only through Microsoft Support |
| A departed user's OneDrive | 30 days by default, configurable up to 10 years |
| A Microsoft 365 group, with its team and site | 30 days, not configurable |
| A Teams channel | 21 days |
There are also two useful rollback tools: Restore your OneDrive and Restore this library in SharePoint roll files back to any point in the last 30 days.
These windows handle everyday mistakes. They do not handle a mistake discovered in month four, files a departing employee deleted that nobody misses until the recycle bin has been cleared, or ransomware that encrypts a whole library.
Why retention policies are not a backup
Retention policies, retention labels and litigation hold keep copies of content for compliance, and they are worth having. But Microsoft's own backup FAQ points out their limits:
- Legal holds "retain data, but that feature is optimized for export (for example, via eDiscovery), not for mass restore."
- Version history "doesn't scale well for large-scale ransomware attacks," and versions can run out.
- Microsoft's disaster-recovery copies keep "the current state of content, not any historical versions."
Retention answers "can we prove what existed?" A backup answers "can we put everything back the way it was on Tuesday, quickly?" Most companies need both.
Your options
Microsoft 365 Backup is Microsoft's own backup service, generally available since 2024. It protects Exchange Online mailboxes, OneDrive accounts and SharePoint sites, with restore points as often as every 10 minutes, and a configurable recovery window of up to two years. It is billed pay-as-you-go through an Azure subscription, per gigabyte of protected data, and restores are included. Teams is not a separate workload, although team files live in SharePoint and are covered there.
Third-party backup products do the same job with their own storage, restore tools and pricing. Microsoft's ransomware guidance recommends evaluating Microsoft 365 Backup or a partner solution built on Microsoft 365 Backup Storage, and warns that tools which only copy data elsewhere may not restore quickly enough after an attack.
Doing nothing is also a choice, and it leaves you with the windows in the table above.
How to decide
Answer four questions before choosing a product:
- How far back do you need to go? A few weeks, a year, several years?
- How quickly must you be working again? After a single deleted file, and after ransomware on every SharePoint site.
- Which data matters? Mail, OneDrive, SharePoint and Teams files, and who owns them.
- Who can restore, and has anyone tried? A backup that has never been test-restored is a hope, not a plan.
We set up and run Microsoft 365 backup and compliance, alongside identity and access security that makes the incident less likely in the first place.
Sources
- Microsoft Learn: Shared responsibility in the cloud
- Microsoft Learn: Microsoft 365 Backup FAQ and overview
- Microsoft Learn: Microsoft 365 Backup pricing
- Microsoft Learn: Recoverable Items folder in Exchange Online
- Microsoft Learn: SharePoint and OneDrive data resiliency
- Microsoft Learn: OneDrive retention for deleted users
- Microsoft Learn: Restore a deleted Microsoft 365 group
- Microsoft Learn: Ransomware protection in Microsoft 365
Written by
Stefan Šošić
Co-founder & CEO, BCILITY · Microsoft MVP
Stefan co-founded BCILITY and is a Microsoft MVP. He writes about Business Central development, AL performance, telemetry and AppSource on his own blog.
