Skip to main content
IT KORR
IT KORRKeeping Organizations Reliable & Resilient
Guidance

Does Microsoft 365 Include Backup?

No — not in the sense the word normally means. Microsoft 365 provides retention: deleted data is held for a documented, finite period and is then permanently removed. It does not provide independent, point-in-time restore outside those windows, and Microsoft’s own shared-responsibility position is that the customer retains responsibility for their data.

That is a retention arithmetic problem, not a threat. The useful question is not whether something terrible might happen — it is whether the windows below are longer than the interval at which your organisation would actually notice something missing. This page sets out what each service retains by default, which familiar features are not backup and why, where the responsibility boundary sits, and six questions that decide whether independent backup is warranted in your case.

On the figures below.These are Microsoft’s documented defaults, and several are tenant-configurable — an administrator may already have changed yours. Treat them as the starting point for checking your own tenant, not as a statement of what your tenant does.

What Microsoft Retains

Default retention, service by service

The third column is the one that matters commercially: not what the platform does, but the gap between the retention window and the point at which an organisation typically notices.

  • Exchange Online — items deleted by a user

    Retained
    Moved to Deleted Items. Retained there until the user empties the folder or any configured retention policy acts on it.
    Then
    Moves to Recoverable Items, invisible to the user in normal Outlook use.
    Where this bites
    The user believes the item is gone and will not ask for it back until well after the window has closed.
  • Exchange Online — items purged from Deleted Items

    Retained
    Held in Recoverable Items for 14 days by default. Configurable by an administrator up to 30 days.
    Then
    Permanently removed. Not recoverable by the administrator, and not recoverable by Microsoft support.
    Where this bites
    Two weeks is shorter than the interval at which most organisations discover a mistaken deletion.
  • Exchange Online — a deleted mailbox

    Retained
    Soft-deleted and recoverable for 30 days after the user account is deleted, by default.
    Then
    Removed permanently.
    Where this bites
    Offboarding and licence reclamation routinely happen faster than the business realises it still needed the mailbox contents.
  • OneDrive — files deleted by a user

    Retained
    First-stage recycle bin, then second-stage recycle bin — 93 days total across both stages.
    Then
    Permanently removed.
    Where this bites
    The 93 days are cumulative across both bins, not 93 days in each. This is widely misread.
  • OneDrive — after the user account is deleted

    Retained
    The OneDrive is retained for 30 days by default. An administrator can configure this between 30 and 3,650 days.
    Then
    Removed permanently once the configured window elapses.
    Where this bites
    The default is 30 days and most tenants never change it. Departing-employee data is the single most common irrecoverable loss in Microsoft 365.
  • SharePoint Online — files and list items

    Retained
    First-stage and second-stage recycle bins, 93 days total.
    Then
    Permanently removed.
    Where this bites
    Versioning protects against overwrite, not against deletion — if the item is deleted, its version history goes with it.
  • SharePoint Online — a deleted site

    Retained
    Held in the site-collection recycle bin for 93 days by default.
    Then
    Permanently removed.
    Where this bites
    A deleted site takes every library, list and version history inside it.
  • Microsoft Teams

    Retained
    Teams has no retention of its own. Channel files live in the team’s SharePoint site and follow SharePoint’s behaviour; chat messages live in hidden folders in Exchange mailboxes and follow Exchange’s.
    Then
    Whatever the underlying service does.
    Where this bites
    Teams looks like one product and is retained as three. Reasoning about "Teams backup" as a single thing produces wrong answers.

Retention Is Not Backup

Six things routinely mistaken for backup

Each of these is a real, useful capability. None of them is a restore, and the difference only becomes visible at the moment it matters.

  • Retention policies (Microsoft Purview)

    They are a compliance control. A retention policy prevents data being permanently removed before a defined period — genuinely useful, and it does close part of the gap above. What it does not do is restore. Recovering content held only by a retention policy means an eDiscovery search and export, performed by someone with the right role, producing a file to re-import by hand. That is an evidence-production workflow, not a recovery workflow, and it is measured in days.

  • Litigation hold

    Same category and same limitation, narrower scope. It preserves a mailbox against deletion. It does not return a mailbox to the state it was in last Tuesday.

  • Version history

    Protects against a bad edit, not a deletion. Delete the file and its versions are deleted with it. It also offers nothing against a ransomware process that encrypts in place and then writes enough new versions to push the clean ones out of the retained set.

  • The recycle bin

    A finite, fixed-length grace period, not a recovery point. You cannot choose a date to return to; you can only retrieve what has not yet aged out.

  • Geo-redundancy

    The most commonly conflated item on this list. Microsoft replicates your data across datacentres so that a hardware or site failure does not lose it. Replication faithfully copies a deletion too. Redundancy answers "did Microsoft lose it"; backup answers "did we".

  • Files Restore / self-service restore

    Genuinely a restore, and genuinely useful — a OneDrive or SharePoint library can be rolled back to a point in the last 30 days. But it is bounded to those 30 days, scoped to one library at a time, and does not cover Exchange at all.

Responsibility Boundary

Who owns what in Microsoft 365

The boundary is documented by Microsoft and is not controversial. It is simply not what most organisations assume when they buy the platform.

  • Physical and platform infrastructure

    Microsoft

    Datacentres, hardware, hypervisor, network, platform availability, and replication between datacentres.

  • Service availability and resilience

    Microsoft

    Keeping the service running and recovering it from platform-side failure. This is what the service-level commitments cover.

  • Your data

    You

    Microsoft’s own shared-responsibility position is that the customer retains ownership of and responsibility for their data. Accidental deletion, malicious deletion, a compromised administrator, a misconfigured sync, and retention expiry are all customer-side events.

  • Identity, access and configuration

    You

    Who holds Global Administrator, whether MFA is enforced, what Conditional Access permits, and what retention is configured. Most real data-loss events in Microsoft 365 begin here rather than at the storage layer.

  • Recovery objectives

    You

    Microsoft does not know your RTO or RPO and has made no commitment against them. Nothing in the platform is designed around a recovery-time target you have not stated.

Read the table in one direction and it says something simple: Microsoft is accountable for the service continuing to exist, and you are accountable for what is in it. Every data-loss scenario that actually occurs in practice — a deletion, a compromised administrator, a sync that went the wrong way, a retention window that elapsed — sits on the second half of that sentence.

Decision

Six questions that decide whether you need independent backup

Not every organisation does. Where retention windows comfortably exceed the interval at which a loss would be noticed, and no longer obligation applies, the platform may genuinely be sufficient.

  1. Can you state, without checking, how far back you could restore a deleted SharePoint site?

    If nobody knows the answer, the organisation is relying on a retention window it has not examined. That is the common case, and it is the cheapest thing on this list to fix.

  2. Does your retention exceed the interval at which you would notice a problem?

    Quiet losses — an archive folder, a closed matter, a former employee’s OneDrive — surface months later. A 30-day default does not survive that arithmetic.

  3. Has a restore actually been performed, end to end, in the last twelve months?

    An untested recovery path is a hypothesis. This is the same argument as backup success versus recovery readiness, applied to a platform most organisations never think to test.

  4. Do you have a regulatory or contractual retention obligation longer than 93 days?

    Where one exists, platform defaults do not meet it and a retention policy alone will not produce the restore the obligation implies.

  5. Could a single compromised administrator account delete across every service at once?

    Where administrative access is concentrated, every in-platform protection shares one blast radius. Independent backup is the only control that sits outside it.

  6. Who would perform the restore, and does that person know how?

    The answer is frequently "the IT provider", and the answer to whether this has been rehearsed is frequently no.

If the honest answers are that your retention windows are long enough, your obligations are short, and a restore has been tested — you do not need to buy anything. That is a real outcome of this exercise and worth saying, because the rest of this category is written on the assumption that it never is.

FAQ

Common Questions

Does Microsoft 365 include backup?

No — not in the sense the word normally means. Microsoft 365 includes retention: deleted data is held for a documented, finite period and then permanently removed. Exchange Online retains purged items for 14 days by default (configurable to 30); SharePoint and OneDrive retain deleted content for 93 days across both recycle-bin stages. What the platform does not provide is independent, point-in-time restore outside those windows. Microsoft’s own shared-responsibility position is that the customer retains responsibility for their data.

What does Microsoft retain after a user deletes something?

It depends on the service. Exchange: Deleted Items, then Recoverable Items for 14 days by default (up to 30 if an administrator has raised it). OneDrive and SharePoint: a first-stage and a second-stage recycle bin totalling 93 days — cumulative across both stages, not 93 days in each. A deleted user’s OneDrive is retained for 30 days by default. Teams has no retention of its own: channel files follow SharePoint and chat messages follow Exchange. These are tenant-configurable defaults, so verify them against your own tenant rather than assuming.

Is a Microsoft 365 retention policy the same as backup?

No. A retention policy prevents data being permanently removed before a defined period, which genuinely helps. But recovering content that exists only because of a retention policy means running an eDiscovery search, exporting the result, and re-importing it by hand. That is an evidence-production process measured in days, not a restore. A retention policy answers "is it still there"; a backup answers "can we put it back, by Tuesday lunchtime".

Does Microsoft’s geo-redundancy protect us from data loss?

It protects against Microsoft losing your data through hardware or datacentre failure. It does not protect against you losing it. Replication copies a deletion to every replica just as faithfully as it copies a new file. Redundancy and backup answer two different questions and are routinely conflated.

Does ransomware affect Microsoft 365 data?

It can. The common path is not an attack on Microsoft’s platform but a compromised account or an infected endpoint synchronising encrypted files up through OneDrive, so the cloud copy becomes the encrypted copy. Version history helps up to a point and can be exhausted. The structural issue is that every in-platform protection is reachable with sufficient privilege, so a compromised administrator and the recovery mechanism share one blast radius.

What happens to a departing employee’s mailbox and OneDrive?

By default the mailbox is recoverable for 30 days after the account is deleted, and the OneDrive is retained for 30 days — configurable by an administrator up to 3,650 days, though most tenants never change it. Because licence reclamation usually happens quickly and the business often does not realise what the person held until later, departing-employee data is the most common irrecoverable loss we see in Microsoft 365.

What recovery objectives should we set for Microsoft 365?

The same way you would for any other system holding operational data: decide how much data you could lose (RPO) and how long you could operate without it (RTO), per workload rather than for the tenant as a whole. Mail, active project files and archived records usually warrant different answers. The point of writing them down is that nothing in the platform is designed around a target you have not stated.

How often should a Microsoft 365 restore be tested?

At least annually, and after any material change to tenant configuration or to who administers it. A test is only meaningful if it is a genuine restore of a real item to a usable state, performed by whoever would do it in an incident — not a confirmation that a job reported success.

Do law firms need Microsoft 365 backup specifically?

The obligations that apply are usually client-file retention and the duty to preserve, both of which commonly run far longer than 93 days — so platform defaults do not satisfy them on their own. The practical risk is a closed matter: a file nobody touches for a year, deleted during a tidy-up, discovered missing when the matter reopens. By then every platform retention window has closed.

Does independent backup remove the need for retention policies?

No, and they should not be traded off against each other. They do different jobs. A retention policy enforces that data is kept and can be produced for a legal or regulatory obligation. Backup provides a point-in-time copy that can be restored operationally, held outside the tenant’s own administrative blast radius. Most regulated organisations need both.

Microsoft 365 Recovery

Find out what your tenant would actually restore

A review of your current retention configuration against the windows on this page, the recovery objectives your workloads warrant, and whether a restore has ever been tested end to end. You get the findings either way.

We respond within one business day.

Build: 4fb1bc8 | Built: Oct 6, 2026 8:27 PM EDT