Microsoft 365 Backup: The Gap Most Businesses Do Not Know They Have
Ask most business owners whether their Microsoft 365 data is backed up and they will say yes, because Microsoft runs it and Microsoft is enormous. Ask what would happen if a mailbox were deleted eighteen months ago and needed restoring today, and the answer changes. This is the shared responsibility model, what it means in practice, and where the gap sits.
What Microsoft is actually responsible for
Microsoft guarantees the availability and resilience of the service. Their infrastructure is redundant, their data centres are replicated, and if a disk or a data centre fails your service continues. That is a genuine and substantial commitment, and it is what people are thinking of when they say Microsoft backs it up.
What Microsoft does not do is protect your data from you, or from someone acting as you. Deletion, malicious or accidental, ransomware encryption, a departing employee clearing a mailbox, a misconfigured retention policy: these are your responsibility under the agreement, and the service will faithfully replicate the destruction across every redundant copy.
Retention is not backup
Microsoft 365 has recovery features and they are useful. Deleted items sit in a recoverable folder for a period. Deleted mailboxes and sites can be restored within a window. Retention policies and litigation hold can preserve content for longer where configured.
None of these are backup, for three reasons. They are time-bounded, so anything discovered after the window has passed is gone. They are configuration, so a mistake or a malicious change to the policy affects the protection itself. And they are inside the same tenant, so an attacker with sufficient privilege can alter or remove them.
The practical test is the one that catches everyone: can you restore a specific file to a specific point in time from two years ago, quickly, without knowing in advance that you would need it? With retention alone the answer is usually no.
Where the gap bites
A departing employee is the most common. Someone leaves, their licence is removed to save cost, and the mailbox is deleted after the grace period. Nine months later a contract dispute needs their email and it is unrecoverable.
Ransomware is the most severe. Files synced from an encrypted endpoint into SharePoint or OneDrive replicate the encryption, and version history helps only if the attacker did not exhaust it, which competent ones do.
The quietest is gradual drift: a retention policy set once, never reviewed, quietly deleting content nobody realised was in scope. This one usually surfaces during an audit or a legal request rather than an incident, which is worse in some ways because you had no warning.
What to do about it
Decide what your actual retention requirement is, driven by legal, regulatory and commercial need rather than by what the platform happens to do. Most UK businesses have obligations measured in years, and platform defaults are measured in days or months.
Put third-party backup in place for Exchange Online, SharePoint, OneDrive and Teams, held outside the tenant with separate credentials so that a compromise of your tenant does not reach it. Confirm the restore granularity you need, which is usually item-level rather than whole-mailbox.
Then test a restore, and record how long it took. Every point in this article is theoretical until someone has actually restored something.