“It’s in the cloud, so it’s backed up.” We hear this a lot, usually from a business owner who has just found out it is not quite true. Microsoft looks after Microsoft 365 extremely well. Their data centres will not lose your email in a fire. But keeping the service running is not the same thing as keeping a copy of your data you can go back to, and the difference only becomes obvious on the day you need it. Here is what Microsoft actually does, what it does not, and what to do about the gap.
What Microsoft promises, and what it does not
Microsoft’s job is to keep the service up and your data intact against failures on their side: hardware dying, a data centre going offline, that sort of thing. They do this very well, with multiple copies of everything spread across locations. If you are worried about Microsoft losing your data, you can stop.
What Microsoft does not promise is to protect you from yourself, your staff, or a criminal using one of your accounts. If someone deletes a folder, overwrites a file, or a ransomware infection encrypts everything in a shared library, Microsoft faithfully stores the deleted, overwritten or encrypted version, because from their side that is simply what you asked for. Their own service terms say as much: they recommend you keep your own backups. This idea is usually called shared responsibility. Microsoft is responsible for the service; you are responsible for your data.
How long you really have to get something back
Microsoft 365 does have some built-in safety nets, and for everyday mistakes they are often enough. The problem is that each one has a time limit, and most people do not know what it is until it has passed.
- Deleted email. When someone empties their Deleted Items folder, the message goes to a hidden “recoverable items” area for 14 days by default (an administrator can extend this to 30). After that, it is gone.
- Deleted files in OneDrive and SharePoint. Deleted files sit in a recycle bin for 93 days, then disappear for good. If someone deletes a whole folder and nobody notices for four months, there is nothing to restore.
- Overwritten files. OneDrive and SharePoint keep previous versions of files, which is genuinely useful for “I saved over the wrong document”. It is less useful when ransomware has created hundreds of new versions of thousands of files, and you need to roll an entire library back to Tuesday afternoon.
- A departed staff member’s data. When you delete a user account, their mailbox and OneDrive are kept for 30 days and then removed. Unless someone has put a hold on it or moved the data, that is the end of it.
Retention policies, which some businesses set up for legal or professional reasons, can keep things longer, but they are designed for compliance, not recovery. They are good at proving what an email said; they are slow and awkward for putting a whole department’s files back where they were.
The common thread: the built-in tools help you undo a small mistake you noticed quickly. They are not designed for the scenarios that actually threaten a business, which are large, deliberate, or discovered late.
The scenarios that catch businesses out
Ransomware. Modern ransomware does not just encrypt the laptop it lands on. It reaches into the files that laptop can see, including SharePoint libraries synced to the desktop. We wrote about how these attacks have changed in ransomware in 2026; the short version is that they now hunt for backups first, which is exactly why insurers ask whether yours are kept somewhere a stolen password cannot reach.
A disgruntled or careless person. An employee on their way out deletes the client folder, or empties a shared mailbox, and it is not discovered until after the recycle bin has done its 93 days.
A compromised account. Someone gets into a mailbox, sets up forwarding, deletes the evidence, and purges the recoverable items. Account takeover often comes with deliberate clean-up.
Something nobody noticed. A sync error quietly removes a few hundred files in a folder nobody opens often. Six months later someone needs one of them.
None of these are rare, and none of them are Microsoft’s fault. They are also exactly the cases the Essential Eight has in mind when it lists regular backups as one of the eight things every business should do.
Your options
There are two sensible ways to close the gap, and they suit different businesses.
Microsoft’s own backup service
Microsoft now sells Microsoft 365 Backup, which is a proper backup product rather than a safety net. It takes a snapshot of your mailboxes, OneDrive accounts and SharePoint sites every ten minutes for the most recent two weeks, then keeps weekly snapshots going back as far as two years, depending on the policy you choose. Restoring is fast because the backups live inside Microsoft’s own systems, and the backup copies are stored in a way that cannot be altered once written, so an attacker who gets into your account cannot encrypt them.
It is priced on how much data you protect rather than per person, at a per-gigabyte monthly rate, with restores free. For a typical small business that is modest money. The honest limitation is that your backup still lives with the same provider as your data and under the same administrator accounts, which some businesses, insurers and auditors are not comfortable with.
A separate backup kept outside Microsoft
The other option is a third-party backup service that copies your Microsoft 365 data to storage Microsoft does not control, with its own logins. This is the traditional “keep a copy somewhere else” approach, and it has two advantages: it survives anything that happens inside your Microsoft 365 account, including a complete administrator compromise, and it usually keeps data for as long as you like without the per-gigabyte meter running in the same way.
The trade-offs are that restores of large amounts of data are slower, because everything has to be copied back in from outside, and it is one more system to look after.
Which one?
For most of the small businesses we work with, the deciding questions are: does your insurer or a professional standard require the backup to be separate from your main systems, and how fast would you need everything back after a bad day? Businesses with a strict separation requirement tend to go third-party. Businesses that want the fastest possible recovery and are comfortable keeping it within Microsoft tend to go with Microsoft’s service. Some do both, using Microsoft’s for day-to-day fast recovery and a separate copy as the last line.
The bit people skip: testing
Whichever you choose, a backup you have never restored from is a hope, not a plan. Once a quarter, pick a file, a folder and a mailbox and restore them somewhere harmless. Time how long it takes. Write it down. The cyber insurance questionnaire you fill in at renewal will ask when you last did this, and “never” is not a good answer.
What we would do
If you have Microsoft 365 and no backup beyond the recycle bin, this is one of the first things we fix as part of managed Microsoft 365: choose the right option for your obligations, switch it on for every mailbox and library, and test a restore so you know it works before you need it. If you are not sure what you currently have, or whether the backup someone set up years ago is still running, we are happy to check and tell you plainly. Get in touch.
Adam leads the Itopia team in Brisbane, helping professional-services firms get secure, productive and confident with their technology, in plain English.

