
If your business runs on Microsoft 365, it is easy to assume your data is safe. Everything lives in the cloud, Microsoft is one of the largest technology companies on earth, and the service almost never goes down. So surely your email, files and documents are backed up automatically? It is one of the most common misunderstandings in small business IT, and it catches people out at the worst possible moment: after something important has already been deleted.
The truth is that Microsoft 365 is a highly reliable platform, but reliability is not the same as backup. Microsoft keeps the service running and available. Protecting the actual contents of your mailboxes, your SharePoint sites and your OneDrive files is, by Microsoft’s own design, your responsibility. This guide explains why that gap exists, what the built-in safety nets really do, and how to close the risk without overcomplicating things.
The comfortable assumption that catches businesses out
Picture a common scenario. A staff member leaves, and a few weeks later their Microsoft 365 account is removed to save on licensing. Months after that, you realise an important set of files or emails only ever existed in that person’s account. You log a ticket expecting Microsoft to restore it, and discover the data is simply gone.
Or a simpler version: someone deletes a folder of client records, empties the recycle bin to tidy up, and nobody notices for a few months. By the time the loss is discovered, the built-in recovery window has closed. In both cases the business assumed a backup existed, when what actually existed was a short grace period that had already expired.
Microsoft runs the service, you own the data
Microsoft operates what it calls a shared responsibility model. In plain terms, Microsoft is responsible for the things it controls: keeping the servers online, patching the platform, defending its data centres, and making sure the service is available when you log in. You, the customer, remain responsible for your own data and how it is used, including protecting yourself against accidental deletion, malicious deletion and the loss of files when accounts are removed.
This is not a loophole or fine print. It is stated plainly in Microsoft’s own service terms, which recommend that customers regularly back up the content they store on the service using third-party tools. Microsoft protects the platform from its failures. It does not promise to protect your business from your own mistakes, a disgruntled employee, or an attacker who logs in with a stolen password.
What the built-in recycle bins and retention actually do
Microsoft 365 does include some genuinely useful native recovery features. The problem is that they are designed for short-term “oops” moments, not for long-term protection, and their limits are easy to hit without realising.
- OneDrive and SharePoint. Deleted files sit in a recycle bin for 93 days by default, after which they are permanently removed.
- Departed staff. When a user’s account is deleted, their OneDrive is retained for only 30 days by default before it begins to be removed, which is often far shorter than the time it takes to notice something was lost.
- Email. Deleted messages are recoverable for a limited window, typically a matter of weeks, before they are purged for good.
- Retention policies. These can hold data for longer, but they are a compliance and legal-hold tool, not a backup. They are complex to configure, easy to misconfigure, and do not give you the simple point-in-time restore you would want after a disaster.
The key point is that all of these are measured in days, and the clock is often already running before you know there is a problem. A backup, by contrast, is a separate copy you control, kept for as long as you decide, that you can restore from at any time.
The gaps a real backup is there to fill
Once you accept that the native tools are a grace period rather than a safety net, the value of a proper backup becomes clear. A dedicated Microsoft 365 backup protects you against the situations that quietly cause the most pain:
- Accidental deletion discovered too late. Files or emails removed months ago, well outside the recycle bin window, can still be restored.
- Malicious deletion. A departing or disgruntled staff member who wipes their mailbox and files cannot erase a copy they do not control.
- Ransomware and account takeover. If an attacker gets into an account and encrypts or deletes cloud data, an independent backup is what gets you back on your feet.
- Lost accounts. When you remove a licence to save money, the data attached to that account does not vanish from your backup.
- Misconfigured retention. If a policy is set up incorrectly and data is purged, a separate backup is not affected by that mistake.
This is the same logic behind the 3-2-1 backup rule: keep more than one copy, in more than one place, so that no single failure or attacker can take out both your live data and your ability to recover it.
What to look for in a Microsoft 365 backup
You do not need enterprise-grade complexity to do this well. Most small and medium businesses use a third-party cloud backup service that connects to Microsoft 365 and runs quietly in the background. When you compare options, look for a few practical qualities:
- Full coverage. It should protect Exchange (email), OneDrive, SharePoint and Teams, not just mailboxes.
- Automatic and frequent. Backups should run on a schedule without anyone remembering to press a button.
- Sensible retention. You should be able to keep data for the period your business and your industry require, not just a few weeks.
- Simple restore. Recovering a single email, a folder or an entire account should be quick and self-service, because the moment you need it is rarely a calm one.
- Independent storage. The backup should live separately from your Microsoft 365 tenant, so a compromise of one does not take the other with it.
- Security built in. Look for encryption and multi-factor authentication on the backup console itself, so the safety copy is not an easy target.
A Microsoft 365 backup is one piece of a bigger picture, and it works best alongside the other fundamentals. Strong authentication reduces the chance an attacker gets in to cause damage in the first place, which is why multi-factor authentication matters so much for cloud accounts. Reliable backups are then what let you recover calmly if prevention fails, which is exactly the position you want to be in during a ransomware incident.
Find out where you stand
Microsoft 365 is an excellent platform, but it was never meant to be your backup. The businesses that get caught out are almost always the ones that assumed otherwise, right up until the day they needed to restore something and could not. Closing that gap is inexpensive, quick to set up, and one of the most reassuring things you can do for your business.
Not sure whether your backups, or the rest of your defences, would hold up? Take our free cyber security assessment. It takes 5 to 10 minutes, covers 27 practical questions mapped to the ACSC Essential Eight, ISO 27001 and SOC 2, and gives you an instant PDF report showing where you stand and the clear steps to close the gaps.