Microsoft 365 is not a backup — what happens when someone deletes the wrong folder
Microsoft's default retention on deleted 365 data is 30 to 90 days. After that, gone. Here's the difference between retention and backup, and what actually protects your business.
A call we get every few months goes something like this: an office manager cleaned up SharePoint over the weekend, deleted a folder they thought was old, and now on Monday morning three departments can't find critical files. Panic sets in around 10 AM when they realize the recycle bin also got emptied. By noon they're on the phone with us.
Sometimes we can get it back. Sometimes we can't. The difference isn't luck — it's whether the business had actual backup, or was relying on the Microsoft 365 built-in retention and assuming that counted.
Retention is not backup. Here's what Microsoft actually gives you.
Microsoft 365 has retention windows for deleted content, and if you catch a mistake fast enough, they can save you. But the windows are much shorter than most business owners think.
- Deleted email: stays in the Deleted Items folder until the user empties it. After that, sits in Recoverable Items for 14 days by default (extendable to 30 with the right licensing). After that, gone.
- OneDrive files: deleted files go to the user's Recycle Bin for 30 days, then a second-stage recycle bin for another 30 days. After 60 days total, gone.
- SharePoint sites and files: similar two-stage recycle bin, 93 days combined. After that, gone.
- Teams messages: retention depends on your Teams retention policy, which most businesses have never configured. Default: kept indefinitely on Microsoft's servers, but there's no easy self-serve way to restore a specific deleted message from history.
- Mailbox retention hold (litigation hold): only kept if enabled per-user and only for the duration you specify. Not on by default.
The critical thing: these are retention windows, not backups. They exist so Microsoft can guarantee the service works and so users can recover from obvious mistakes quickly. They're not designed for the "we need to restore what an ex-employee's email looked like in Q3 last year" case that comes up in litigation, audits, or compliance work. And they're absolutely not designed for the ransomware case, where an attacker has time to delete the recycle bins along with the primary data.
Microsoft themselves recommend third-party backup for exactly these reasons. Their Services Agreement, Section 6b, states directly: "We recommend that you regularly backup Your Content and Data … using Third-Party Apps and Services."
The three scenarios that catch businesses off guard
1. The departing employee
Someone leaves the company. IT deletes their account per policy — usually within a week or two of departure. Three months later, a claim comes in from a client referencing an email conversation that employee had with them. You need the email to defend against the claim. It's gone — well past the retention window on a deleted account.
With third-party backup, that mailbox is preserved indefinitely and you restore the specific emails in minutes. Without it, you're explaining to your lawyer that the evidence doesn't exist.
2. The Monday morning cleanup
Well-meaning office manager cleans up SharePoint, empties recycle bins to free space (which doesn't actually help anything but they don't know that), and takes out folders that turn out to have been in active use by a department they don't work with. Discovered a week later. Two of the folders are still in the second-stage recycle bin; three are gone.
With third-party backup, you restore the site to its state from the day before the cleanup. Without it, you're explaining what happened in a very uncomfortable meeting.
3. Ransomware
An attacker gets into a user's account (usually via phishing that bypassed MFA somehow, or a session-token theft). They spend several days quietly deleting SharePoint files, dumping mailboxes, and clearing recycle bins as they go. By the time the attack is discovered, the primary data AND the retention windows are both empty.
With third-party backup — especially one designed for ransomware resilience — you roll SharePoint back to the day before the attack started. Without it, you're paying the ransom or accepting the loss.
How to tell if you actually have backup
Three-question test:
- Ask your IT provider: "If we lost all our SharePoint data today, how far back could you restore from, and how long would it take?" If the answer involves the words "recycle bin," you don't have backup — you have retention. If the answer is "we could restore to any daily snapshot going back years, in under an hour," you have backup.
- Ask when the last actual restore test happened. A backup that's never been tested restoring is not really a backup. It's an assumption.
- Ask where the backup data physically lives. If it's in the same Microsoft tenant as your primary data, it's not really independent — a compromise of your tenant compromises both.
What we recommend
Our Cloud Workspace Backup service covers Microsoft 365, Google Workspace, and Hosted Exchange with daily backup, unlimited retention, and one-click restore of any user's mailbox, files, or SharePoint site. Data is stored in Canadian datacentres, independent of your Microsoft tenant. It's available as an add-on to any of our managed IT tiers, priced per user.
But even if you don't use us, use somebody. Microsoft 365 without third-party backup is one accidental delete or one compromised account away from a data loss you can't recover from.
Not sure if your M365 data is actually backed up?
We'll do a free walkthrough of your current backup and retention posture, and tell you straight where the gaps are. No obligation, no sales pitch.