Microsoft 365 is not a backup
It is a common assumption, and it is the one that costs people their files.
We get asked to restore something from Microsoft 365 fairly often. Sometimes we can. Sometimes the answer is that it went a while ago and there is nothing to go back to.
The confusion is understandable. The data is in the cloud, Microsoft is a serious company, so surely it is safe. It is safe from the things Microsoft is responsible for. Those are not the things that usually go wrong.
Who is responsible for what
Microsoft runs the service. The data centres, the network, keeping it available, and replicating your data across sites so that a hardware failure does not lose it. That part is genuinely well done.
Your data is yours. Accidental deletion, someone clearing out a mailbox on their way out of the door, ransomware encrypting files that then sync, a retention policy set up wrongly, an account compromise used to destroy things deliberately. None of that sits on Microsoft’s side of the line.
Replication is not backup
This is the bit worth understanding properly. Microsoft copies your data across multiple locations so it survives a failure. But a copy is a copy. If a file is deleted, the deletion replicates. If a file is encrypted, the encryption replicates. You end up with several identical copies of the problem.
The clock is shorter than people expect
Exchange Online retains deleted items for 14 days by default. An administrator can extend that to 30. After that the ordinary route back is gone. Recycle bins have quotas, they empty, and someone with a compromised administrator account can empty them on purpose.
Thirty days sounds ample until you think about how these things are actually discovered. Nobody notices a missing file on the day it goes. They notice in March, looking for something from January.
Microsoft says so themselves
This is not our interpretation. The Microsoft Services Agreement, at section 6b, says: “We recommend that you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services.”
The company running the service recommends you keep your own copy of what is in it.
What to actually do
- Find out your current retention window. Not what you assume it is, what is configured.
- Cover the whole tenancy. Mail is what everyone thinks of. OneDrive, SharePoint and Teams hold just as much and are forgotten far more often.
- Test a restore. A backup nobody has ever restored from is a theory. Ask for a specific file back from six months ago and see what happens.
- Keep the copy separate from the thing it protects. A backup living inside the account being attacked is not a backup.
If you are not sure what your retention is set to, it takes a few minutes to check and it is worth knowing before you need it.
Sources
- Microsoft, Microsoft Services Agreement, section 6b, on backing up your own content.
- Microsoft Learn, Recoverable Items folder in Exchange Online, on retention periods and quotas.
- Microsoft Learn, Configure deleted item retention and Recoverable Items quotas.
- Veeam, The Microsoft 365 shared responsibility model. Written by a backup vendor, so read it with that in mind; the division of responsibility it describes matches Microsoft’s own documentation.