Office 365 Backup: Retention Is Not a Backup
"It's in Microsoft 365, so it's backed up." That single assumption causes more permanent data loss for Dutch SMEs than ransomware does. Microsoft runs one of the most reliable cloud platforms in the world, but reliability and backup are two different guarantees, and only one of them is Microsoft's job.
The shared responsibility model, in plain terms
Microsoft's own Shared Responsibility Model draws a clear line between what Microsoft owns and what you own. Microsoft is responsible for the platform: keeping Exchange Online, SharePoint, OneDrive and Teams running, patched and available around the clock. You are responsible for the data inside it — what happens to an email after it's deleted, what happens to a file after a user leaves the company, what happens after ransomware encrypts a synced OneDrive folder. Microsoft's own documentation is explicit that customers need their own data protection strategy on top of the built-in retention features it ships. That one line is the reason this article exists, and the reason so many SMEs discover the gap only after losing something they needed back.
Why this catches so many SMEs off guard
Most SMEs that migrated from an on-premises Exchange server or a file server had backup as a visible, separate line item: a NAS in a cupboard, a tape rotation, a contract with a backup vendor. Moving to Microsoft 365 removed that visible infrastructure — and with it, the visible reminder that backup is something you have to arrange yourself. Nothing about the migration was careless; the topic simply stopped coming up in IT planning conversations, because Microsoft 365 *feels* like something that takes care of itself. It takes care of uptime. It does not take care of your data.
What "native retention" actually gives you
Office 365 ships with recycle bins, version history, and retention or compliance policies. They are genuinely useful, and they are genuinely not a backup:
- They protect against small, recent mistakes. Someone deletes an email or overwrites a file an hour ago — that's exactly what they're built for. They are not built for systematic, delayed, or large-scale loss.
- They are configurable, which means they are also disable-able. An administrator — or an attacker who has compromised an admin account — can shorten or switch off a retention policy from inside the same tenant it's supposed to protect. A backup stored outside the tenant, under separate credentials, cannot be reached that way.
- They are not built for point-in-time restore. Recovering "the whole SharePoint site as it looked last Tuesday" is not what version history or a recycle bin is designed to do; they recover individual items, not a consistent snapshot of an environment.
- They follow the item, not the estate. Retention policies apply per mailbox, per site, per policy. Reconstructing what a departing employee's mailbox and OneDrive looked like together on a specific date is not what they're for.
Where this actually goes wrong
A handful of scenarios account for most of the Microsoft 365 data-loss incidents we see in practice.
| Scenario | What native retention does | What it misses |
|---|---|---|
| An employee leaves and IT deletes the account | The mailbox or OneDrive may be retained briefly, then permanently removed | No easy way to selectively recover just the files a manager needs months later |
| Ransomware encrypts synced OneDrive or SharePoint files | Version history can help, if it wasn't disabled or already exhausted | Large-scale encryption events can outpace version limits, and sync can spread the damage further |
| An admin account is compromised | The attacker inherits the same rights as your IT administrator, including the ability to change retention settings | The safety net protecting you is inside the same blast radius as the attack |
| Accidental bulk deletion during a migration, script, or "clean-up" | The recycle bin catches individual, recent deletions | Bulk deletions or delayed discovery routinely fall outside that window |
| A legal hold or long-term compliance need | Retention policies can hold data | Changing them still requires the same admin access that's meant to be under scrutiny |
The pattern repeats in every row: the safety net and the thing it's supposed to protect against live inside the same system, administered with the same credentials.
What a real Microsoft 365 backup adds
A dedicated backup solution for Microsoft 365 — covering Exchange Online, SharePoint, OneDrive and Teams — closes exactly that gap:
- A copy stored outside the tenant, so a compromised admin account or a ransomware event inside Microsoft 365 cannot reach it, delete it, or encrypt it.
- Retention that you control, independent of whatever policy Microsoft's defaults or your own IT admin currently apply.
- Granular, point-in-time restore — one email, one file, one Teams channel, or an entire mailbox exactly as it looked on a specific date, rather than whatever the recycle bin happens to still hold.
- Coverage across workloads, not just mail. Teams chat history and SharePoint document libraries are the two most commonly forgotten when an SME assumes "our backup covers Microsoft 365" without checking what's actually included.
What to look for when choosing one
Not every product marketed as a "Microsoft 365 backup" covers the same ground. Before committing to one, check:
- 1. Which workloads are actually included. Exchange, OneDrive, SharePoint, Teams, and Entra ID (Azure AD) objects such as groups, permissions and shared mailboxes are commonly sold as separate add-ons rather than bundled together.
- 2. Where the backup data is stored, and whether that location meets your data residency expectations under the AVG/GDPR.
- 3. How restores actually work. Can a helpdesk technician restore a single file within minutes, or does every restore require opening a support ticket with the vendor?
- 4. Retention length, and whether it's fixed or configurable to match your own compliance needs, which may run longer than Microsoft's own defaults.
- 5. Whether restores are ever actually tested. A backup nobody has restored from is a hope, not a plan — the exact same rule that applies to on-premises backups applies here.
What it typically costs
Dedicated Microsoft 365 backup is usually billed per user, per month, on top of your existing Microsoft 365 licence cost — a small, predictable line item rather than a project. Relative to the cost of permanently losing a mailbox during a legal dispute, or having to explain to a client why three months of shared project files disappeared with ransomware, it is consistently one of the cheapest risk-reduction measures an SME can add to its IT budget. It's also one of the quickest to roll out: adding backup to an existing tenant does not require downtime or any change to how staff already work.
Rolling it out
In practice, adding backup to an existing Microsoft 365 tenant is a short project rather than a migration:
- 1. Inventory which mailboxes, sites and Teams need coverage, and agree retention periods per data type with the business, not just IT.
- 2. Connect the backup solution to the tenant using a dedicated service account with only the permissions it needs.
- 3. Run the initial backup and verify coverage against the inventory before treating it as live.
- 4. Schedule and monitor ongoing backups, with alerts routed to someone who will actually act on a failure.
- 5. Test a restore before you ever need one for real, and repeat that test periodically so it stays trustworthy.
Common myths, corrected
"Microsoft backs up everything automatically." Microsoft backs up its own infrastructure for its own disaster recovery purposes; it does not offer that as a service you can use to recover your deleted or corrupted data. See the shared responsibility section above.
"Version history is basically the same as backup." It protects against the same category of accident a backup does, but not the same range of incidents, and not with independent storage or control. Both are useful; only one is a backup.
"We're too small to be a target." Attackers target Microsoft 365 tenants specifically because the platform is common and often under-protected on the backup side, independent of company size. A small tenant is not a harder target; it's usually an easier one.
"Our IT partner already backs this up." Worth confirming explicitly and in writing rather than assuming. "We manage your Microsoft 365 environment" does not automatically include a dedicated backup product with independent storage — ask specifically what is backed up, where, and for how long.
FAQ
Does Microsoft back up my Office 365 data? No. Microsoft is responsible for keeping the platform running and available. Protecting your data against deletion, ransomware or long-term loss is your responsibility under Microsoft's own Shared Responsibility Model.
What's the difference between retention policies and backup? Retention policies — recycle bin, version history, compliance holds — live inside your tenant and can be changed or disabled by whoever has admin access, including an attacker who has compromised that access. A backup stores a separate copy outside the tenant, under independent control.
We already use OneDrive sync and version history — is that enough? It helps with small, recent, individual mistakes, but it is not a substitute for point-in-time, tenant-wide restore, and it does not survive an attacker who compromises admin credentials or a large-scale ransomware event.
What happens to a former employee's mailbox and OneDrive if we don't back it up? Depending on how the account is offboarded, the data may be retained briefly and then permanently deleted, with no straightforward way to recover just the files a manager needs later, unless it exists in a separate backup.
Is a Microsoft 365 backup required under NIS2 or the AVG? Neither framework names a specific backup product, but both expect organisations to have appropriate, risk-based measures to protect data and recover from incidents. A dedicated backup is one of the more concrete, verifiable ways to demonstrate that for the data your business runs on every day.
Close the gap
Want a clear picture of what is and isn't actually protected in your Microsoft 365 environment? Our Cloud & Infrastructure service covers Microsoft 365 tenant administration and backup, and pairs well with our Cybersecurity & Identity service if ransomware and account compromise are part of your risk picture. See also Preventing Ransomware in the SMB for how backup fits into a wider defence.
