Many businesses assume Microsoft 365 protects their data the way a traditional backup does. It does not, and the gap between what Microsoft actually retains and what you can recover after a ransomware attack or accidental deletion can cost you weeks of work or a regulatory fine.
What Microsoft 365 Actually Covers (and What It Does Not)
Microsoft’s responsibility under the shared responsibility model is to keep the 365 platform running and available. Your data is your responsibility. Here is what Microsoft gives you by default:
- Exchange Online recycle bin: Deleted items stay in the Deleted Items folder until a user empties it. After that, items go to Recoverable Items, where the default retention is 14 days (configurable to 30 days maximum on standard plans).
- SharePoint and OneDrive recycle bin: Files deleted from OneDrive or SharePoint move to the site recycle bin for 93 days, then to a second-stage recycle bin for another 93 days before permanent deletion.
- Version history: SharePoint and OneDrive keep up to 500 versions of a file by default, but version history is not a backup. If ransomware encrypts a file and syncs 500 encrypted versions, your clean copy is gone.
- Microsoft 365 Backup (Microsoft’s own add-on): As of 2024, Microsoft offers a paid Backup add-on that provides faster restore points, but it requires an additional per-user license and is not included in any standard 365 plan.
None of these features give you a long-term, independent, restorable archive that lives outside Microsoft’s infrastructure.
The Four Scenarios Where Microsoft’s Built-In Tools Fail You
Understanding the failure cases tells you exactly what kind of backup you actually need.
- Ransomware encryption via sync client: A user’s OneDrive sync client is compromised. Ransomware encrypts local files, the sync client pushes encrypted versions to the cloud, and version history fills up with encrypted iterations. If you had 500 versions and ransomware cycled through them, your 14- or 30-day retention window may not reach the clean copy.
- Accidental or malicious bulk deletion: An admin or a terminated employee deletes a SharePoint site or an entire mailbox. Site deletions go to a recycle bin for 93 days, but if the deletion happened 94 days ago and you are only discovering it now, the data is gone.
- Litigation hold gaps: Litigation holds in Exchange Online preserve data for compliance, but they do not create a restorable backup. You can export via eDiscovery, but you cannot do a granular mailbox restore directly from a litigation hold without significant IT effort and time.
- Third-party app data: Teams chat, Planner tasks, and some third-party apps integrated into 365 store data outside Exchange and SharePoint. Microsoft’s standard retention policies often do not apply to this data at all.
What a Real Third-Party Backup Gives You
A purpose-built third-party backup for Microsoft 365 adds capabilities that Microsoft’s native tools do not provide:
- Daily or more frequent automated snapshots of Exchange mailboxes, SharePoint sites, OneDrive files, and Teams data, stored in infrastructure separate from Microsoft’s own.
- Granular restore: You can restore a single email, a single document version, or an entire mailbox to a specific point in time, without affecting anything else.
- Long-term retention: Most compliance frameworks, including FTC Safeguards for auto dealerships and HIPAA for healthcare, require retaining records for three to seven years. Third-party backup tools let you set policies that match your legal obligations.
- Immutable storage options: Leading tools such as Veeam Backup for Microsoft 365, Acronis Cyber Protect Cloud, and Datto SaaS Protection support immutable backup storage, meaning a ransomware actor who gains access to your 365 tenant cannot delete or encrypt your backup copies.
- Independent recovery: If Microsoft experiences an outage or your tenant is compromised and suspended, you can still access your backed-up data through the backup platform.
A Dealership Example That Illustrates the Stakes
An auto dealership using Microsoft 365 for email and document storage is subject to the FTC Safeguards Rule, which requires maintaining customer financial records securely. If a ransomware event encrypts the deal jacket files stored in SharePoint and the 93-day recycle bin window has passed, the dealership faces both operational recovery costs and potential compliance exposure. A third-party backup running daily snapshots with three-year retention would make that a restore job measured in hours, not a data loss event.
How to Evaluate and Deploy a Third-Party 365 Backup
Follow these steps to move from no backup to a defensible position:
- Audit your current retention settings in the Microsoft 365 admin center. Document the actual retention windows in place for Exchange, SharePoint, and OneDrive.
- Identify your compliance retention requirements. FTC Safeguards, state privacy laws, and industry regulations set minimum retention periods that should drive your backup policy settings.
- Select a backup tool that stores data outside Microsoft’s Azure tenant. Veeam Backup for Microsoft 365, Acronis Cyber Protect Cloud, and Datto SaaS Protection are established options used by MSPs. Verify where the backup data is stored geographically and confirm immutability options.
- Configure backup frequency. For most businesses, daily backups are the floor. Financial services and dealerships should consider twice-daily backups of critical mailboxes.
- Test restores on a schedule. A backup you have never tested is not a backup. Run a granular restore of a test mailbox and a SharePoint document library quarterly to verify the process works.
- Document your RTO and RPO. Your recovery time objective (how fast you need to be back online) and recovery point objective (how much data loss you can tolerate) should be stated in your business continuity plan so you can verify your backup tool actually meets them.
Get Help from COMNEXIA
COMNEXIA has provided managed IT services and cybersecurity to businesses in the greater Atlanta area for 35 years. If your organization is running Microsoft 365 without a third-party backup in place, we can audit your current configuration, identify your retention gaps, and deploy a solution sized to your compliance requirements. Call us at (877) 600-6550 or contact us to schedule a conversation.