Cloud
Guide

Office 365 Backup: Retention Is Not a Backup

Office 365 keeps running because Microsoft maintains the platform, not because your data is backed up. This guide explains the shared responsibility model, where native retention policies actually fail, and what to look for in a real Microsoft 365 backup.

Aug 28, 2026
8 min read
Office 365 Backup: Retention Is Not a Backup

Office 365 Backup: Retention Is Not a Backup

"It's in Microsoft 365, so it's backed up." That single assumption causes more permanent data loss for Dutch SMEs than ransomware does. Microsoft runs one of the most reliable cloud platforms in the world, but reliability and backup are two different guarantees, and only one of them is Microsoft's job.

The shared responsibility model, in plain terms

Microsoft's own Shared Responsibility Model draws a clear line between what Microsoft owns and what you own. Microsoft is responsible for the platform: keeping Exchange Online, SharePoint, OneDrive and Teams running, patched and available around the clock. You are responsible for the data inside it — what happens to an email after it's deleted, what happens to a file after a user leaves the company, what happens after ransomware encrypts a synced OneDrive folder. Microsoft's own documentation is explicit that customers need their own data protection strategy on top of the built-in retention features it ships. That one line is the reason this article exists, and the reason so many SMEs discover the gap only after losing something they needed back.

Why this catches so many SMEs off guard

Most SMEs that migrated from an on-premises Exchange server or a file server had backup as a visible, separate line item: a NAS in a cupboard, a tape rotation, a contract with a backup vendor. Moving to Microsoft 365 removed that visible infrastructure — and with it, the visible reminder that backup is something you have to arrange yourself. Nothing about the migration was careless; the topic simply stopped coming up in IT planning conversations, because Microsoft 365 *feels* like something that takes care of itself. It takes care of uptime. It does not take care of your data.

What "native retention" actually gives you

Office 365 ships with recycle bins, version history, and retention or compliance policies. They are genuinely useful, and they are genuinely not a backup:

  • They protect against small, recent mistakes. Someone deletes an email or overwrites a file an hour ago — that's exactly what they're built for. They are not built for systematic, delayed, or large-scale loss.
  • They are configurable, which means they are also disable-able. An administrator — or an attacker who has compromised an admin account — can shorten or switch off a retention policy from inside the same tenant it's supposed to protect. A backup stored outside the tenant, under separate credentials, cannot be reached that way.
  • They are not built for point-in-time restore. Recovering "the whole SharePoint site as it looked last Tuesday" is not what version history or a recycle bin is designed to do; they recover individual items, not a consistent snapshot of an environment.
  • They follow the item, not the estate. Retention policies apply per mailbox, per site, per policy. Reconstructing what a departing employee's mailbox and OneDrive looked like together on a specific date is not what they're for.

Where this actually goes wrong

A handful of scenarios account for most of the Microsoft 365 data-loss incidents we see in practice.

ScenarioWhat native retention doesWhat it misses
An employee leaves and IT deletes the accountThe mailbox or OneDrive may be retained briefly, then permanently removedNo easy way to selectively recover just the files a manager needs months later
Ransomware encrypts synced OneDrive or SharePoint filesVersion history can help, if it wasn't disabled or already exhaustedLarge-scale encryption events can outpace version limits, and sync can spread the damage further
An admin account is compromisedThe attacker inherits the same rights as your IT administrator, including the ability to change retention settingsThe safety net protecting you is inside the same blast radius as the attack
Accidental bulk deletion during a migration, script, or "clean-up"The recycle bin catches individual, recent deletionsBulk deletions or delayed discovery routinely fall outside that window
A legal hold or long-term compliance needRetention policies can hold dataChanging them still requires the same admin access that's meant to be under scrutiny

The pattern repeats in every row: the safety net and the thing it's supposed to protect against live inside the same system, administered with the same credentials.

What a real Microsoft 365 backup adds

A dedicated backup solution for Microsoft 365 — covering Exchange Online, SharePoint, OneDrive and Teams — closes exactly that gap:

  • A copy stored outside the tenant, so a compromised admin account or a ransomware event inside Microsoft 365 cannot reach it, delete it, or encrypt it.
  • Retention that you control, independent of whatever policy Microsoft's defaults or your own IT admin currently apply.
  • Granular, point-in-time restore — one email, one file, one Teams channel, or an entire mailbox exactly as it looked on a specific date, rather than whatever the recycle bin happens to still hold.
  • Coverage across workloads, not just mail. Teams chat history and SharePoint document libraries are the two most commonly forgotten when an SME assumes "our backup covers Microsoft 365" without checking what's actually included.

What to look for when choosing one

Not every product marketed as a "Microsoft 365 backup" covers the same ground. Before committing to one, check:

  • 1. Which workloads are actually included. Exchange, OneDrive, SharePoint, Teams, and Entra ID (Azure AD) objects such as groups, permissions and shared mailboxes are commonly sold as separate add-ons rather than bundled together.
  • 2. Where the backup data is stored, and whether that location meets your data residency expectations under the AVG/GDPR.
  • 3. How restores actually work. Can a helpdesk technician restore a single file within minutes, or does every restore require opening a support ticket with the vendor?
  • 4. Retention length, and whether it's fixed or configurable to match your own compliance needs, which may run longer than Microsoft's own defaults.
  • 5. Whether restores are ever actually tested. A backup nobody has restored from is a hope, not a plan — the exact same rule that applies to on-premises backups applies here.

What it typically costs

Dedicated Microsoft 365 backup is usually billed per user, per month, on top of your existing Microsoft 365 licence cost — a small, predictable line item rather than a project. Relative to the cost of permanently losing a mailbox during a legal dispute, or having to explain to a client why three months of shared project files disappeared with ransomware, it is consistently one of the cheapest risk-reduction measures an SME can add to its IT budget. It's also one of the quickest to roll out: adding backup to an existing tenant does not require downtime or any change to how staff already work.

Rolling it out

In practice, adding backup to an existing Microsoft 365 tenant is a short project rather than a migration:

  • 1. Inventory which mailboxes, sites and Teams need coverage, and agree retention periods per data type with the business, not just IT.
  • 2. Connect the backup solution to the tenant using a dedicated service account with only the permissions it needs.
  • 3. Run the initial backup and verify coverage against the inventory before treating it as live.
  • 4. Schedule and monitor ongoing backups, with alerts routed to someone who will actually act on a failure.
  • 5. Test a restore before you ever need one for real, and repeat that test periodically so it stays trustworthy.

Common myths, corrected

"Microsoft backs up everything automatically." Microsoft backs up its own infrastructure for its own disaster recovery purposes; it does not offer that as a service you can use to recover your deleted or corrupted data. See the shared responsibility section above.

"Version history is basically the same as backup." It protects against the same category of accident a backup does, but not the same range of incidents, and not with independent storage or control. Both are useful; only one is a backup.

"We're too small to be a target." Attackers target Microsoft 365 tenants specifically because the platform is common and often under-protected on the backup side, independent of company size. A small tenant is not a harder target; it's usually an easier one.

"Our IT partner already backs this up." Worth confirming explicitly and in writing rather than assuming. "We manage your Microsoft 365 environment" does not automatically include a dedicated backup product with independent storage — ask specifically what is backed up, where, and for how long.

FAQ

Does Microsoft back up my Office 365 data? No. Microsoft is responsible for keeping the platform running and available. Protecting your data against deletion, ransomware or long-term loss is your responsibility under Microsoft's own Shared Responsibility Model.

What's the difference between retention policies and backup? Retention policies — recycle bin, version history, compliance holds — live inside your tenant and can be changed or disabled by whoever has admin access, including an attacker who has compromised that access. A backup stores a separate copy outside the tenant, under independent control.

We already use OneDrive sync and version history — is that enough? It helps with small, recent, individual mistakes, but it is not a substitute for point-in-time, tenant-wide restore, and it does not survive an attacker who compromises admin credentials or a large-scale ransomware event.

What happens to a former employee's mailbox and OneDrive if we don't back it up? Depending on how the account is offboarded, the data may be retained briefly and then permanently deleted, with no straightforward way to recover just the files a manager needs later, unless it exists in a separate backup.

Is a Microsoft 365 backup required under NIS2 or the AVG? Neither framework names a specific backup product, but both expect organisations to have appropriate, risk-based measures to protect data and recover from incidents. A dedicated backup is one of the more concrete, verifiable ways to demonstrate that for the data your business runs on every day.

Close the gap

Want a clear picture of what is and isn't actually protected in your Microsoft 365 environment? Our Cloud & Infrastructure service covers Microsoft 365 tenant administration and backup, and pairs well with our Cybersecurity & Identity service if ransomware and account compromise are part of your risk picture. See also Preventing Ransomware in the SMB for how backup fits into a wider defence.

Microsoft 365
Backup
Cloud
MKB

Related Articles

Cloud

Cloud or On-Premise: The Best Choice for Your Business

Cloud, on-premise or hybrid? For SMBs the right answer depends on cost, control, compliance and continuity, not hype. This guide compares the models honestly, with a cost breakdown, a decision framework and the trade-offs that matter.

Read More
Infrastructure Management

Top Strategies for Effective IT Infrastructure Management in 2025

Comprehensive strategies for managing modern IT infrastructure. Learn about cloud optimization, automation, monitoring, and cost management best practices.

Read More
Managed IT

What Does Managed IT Cost for SMBs? Prices Per User (2026)

How much does managed IT support really cost for an SMB in the Netherlands? This guide breaks down price-per-user tiers, what each package includes, one-off and per-server costs, and how to compare quotes without surprises in 2026.

Read More

Need Help with Your IT Infrastructure?

Let's discuss how we can help transform your IT operations with modern solutions.