Microsoft 365 doesn't back up your data the way you think it does
It's the assumption we correct more than any other. Your data is in the cloud, so someone must be backing it up. Microsoft is very clear that they are not.
Ask ten business owners running Microsoft 365 whether their email is backed up, and nine will say yes. Ask them who does it, and the answers get vague. Microsoft, probably. It's in the cloud, isn't it?
Microsoft publishes something called the Shared Responsibility Model, and it is worth reading once. In plain terms it says Microsoft is responsible for keeping the service running. You are responsible for the data you put in it. They guarantee uptime. They do not guarantee your data.
What native retention actually does
Microsoft 365 has recovery features, and they are genuinely useful. Deleted items sit in a recoverable folder. SharePoint and OneDrive keep version history. Retention policies can hold data for compliance. None of this is nothing.
But these are short-term, policy-bound safety nets, not backup. Deleted mail typically ages out. A deleted user account takes its mailbox and OneDrive with it after a grace period. Retention policies protect what you configured them to protect, and only that. If a policy was never set on a site, there is nothing to fall back on.
Native retention is designed to recover from a mistake you notice quickly. Backup is designed to recover from a disaster you discover late.
The three ways people actually lose Microsoft 365 data
In our experience it is almost never a Microsoft outage. It is one of these:
- Someone deletes something and nobody notices. A departing employee's mailbox is removed to free up a licence. Six weeks later Finance needs an email thread from that account. The grace period has passed.
- Ransomware reaches synced files. Malware encrypts a laptop, OneDrive dutifully syncs the encrypted versions up, and the clean copies age out of version history while the incident is still being investigated.
- A misconfigured policy quietly purges data. Retention settings get changed during a tenant cleanup, and the effect only becomes visible months later when something is needed.
Notice that none of these are exotic. They are ordinary Tuesday problems, and native retention handles none of them well.
What proper Microsoft 365 backup looks like
A real backup is independent of the platform it protects. It runs on its own schedule, stores copies outside the tenant, keeps them for as long as you decide rather than as long as a policy allows, and lets you restore a single item without a support ticket.
Practically, that means covering Exchange Online, SharePoint, OneDrive and Teams together, with point-in-time recovery and granular restore, so you can pull back one email from March without rolling an entire mailbox backwards.
A five-minute test you can run today
Pick a user who left the business more than six months ago. Try to retrieve an email they sent. If you can't, or if it takes a support escalation to find out, you have your answer about where you stand.
Most businesses do this test once and immediately change how they handle Microsoft 365 data. It is not an expensive problem to fix. It is only expensive to discover late.
Not sure what's actually protected in your tenant?
We'll review your Microsoft 365 setup and show you exactly where the gaps are.