Posted on

Microsoft 365 Backup Guide: 5 Gaps SMBs Miss After 93 Days

Microsoft 365 backup and restore review

A Microsoft 365 backup guide has to start with an uncomfortable fact: Microsoft does not back up your data for you in the way most owners assume. What the platform gives you is a set of deletion buffers with expiry dates. Files sitting in a SharePoint or OneDrive recycle bin are recoverable for up to 93 days across the first and second stage bins. Deleted mail lands in the Exchange Online recoverable items folder for 14 days by default, extendable to 30 by an admin. After those windows close, the data is gone, and no support ticket brings it back. A real backup is a second, independent copy with a tested restore path and a time commitment attached to it. Those are two different products, and most small businesses only own the first one.

The Short Version: Why This Microsoft 365 Backup Guide Starts With Retention

Retention is where nearly every Microsoft 365 data loss we get called into actually begins. Not ransomware, not a platform outage. Somebody deleted something, nobody noticed for four months, and the window had already shut. Five principles carry the rest of this article, written for IT directors and operations leads at firms running roughly 10 to 500 seats without a dedicated backup administrator:

  • Retention is a clock, not a copy. Every native recovery path in Microsoft 365 has an expiry date, and the clock starts at deletion, not at discovery.
  • The shared responsibility model puts your data on your side of the line. Microsoft commits to keeping the service running. Recovering your content from your own mistakes is your job.
  • Hold and archive are compliance features, not restore features. Litigation hold preserves; it does not hand a user their mailbox back on a Tuesday morning.
  • Restore granularity is what you actually buy. Recovering a tenant is easy to promise. Recovering one folder, from one mailbox, as of one date, is the thing that saves a workday.
  • An untested restore is a guess. If nobody in the building has run a recovery drill, you do not have a recovery time, you have a hope.

What the Shared Responsibility Model Really Leaves to You

The Microsoft 365 shared responsibility model draws a clean line: Microsoft protects the platform’s availability and infrastructure, and the customer owns the content inside it, including recovery from deletion, corruption, and malicious action by an account holder. That line is in the service documentation, but it rarely makes it into the conversation when a business first moves to the cloud. We see the misread constantly during a migration handover, and it is the single most expensive assumption in the SMB cloud stack.

Does Microsoft Back Up Your Tenant?

Microsoft replicates your tenant data across datacenters for resilience, which is not the same thing as backing it up on your behalf. In agreement with that design, replication is genuinely strong protection against the failure mode it targets: hardware loss, datacenter incidents, and service disruption. Your mail stays available when a disk dies, and you do nothing. In opposition, replication faithfully copies deletions too. When a departing employee empties a mailbox on their last afternoon, every replica agrees the mail is gone. Both readings are correct, and they answer different questions. The honest framing is narrow: replication protects the service, retention protects recent mistakes, and only backup protects a point in time you choose.

Where the Recycle Bin Ends

SharePoint and OneDrive give you a two stage recycle bin totalling up to 93 days, and for everyday accidents that is often enough. A user deletes a folder on Monday, calls on Wednesday, and the restore takes two minutes with no tooling at all. The counter-case is the one that hurts. Long tail deletions, the ones nobody notices, routinely surface during an audit, a client dispute, or a year end close, well past day 93. In our work across Microsoft 365 management for accounting firms, the discovery lag on a missing workpaper set is measured in months, not days. The bin is a rolling window, and the business questions that trigger a search do not respect it.

What Happens On Day 94

On day 94 there is no escalation path. The second stage bin has purged, the item is unrecoverable through the admin center, and Microsoft support cannot reverse it. That is not a service failure, it is the documented behavior working as designed. Firms with a second copy simply restore from it and move on. Firms without one start reconstructing from email threads, local caches, and memory, which is expensive, slow, and frequently incomplete. We have watched that reconstruction consume a week of senior staff time over a folder that a cloud backup service would have returned in twenty minutes.

Retention Policies, Legal Hold and Archive Are Not Restore Paths

Microsoft 365 retention policies, litigation hold, and in place archive all preserve data, and none of them is designed to give a user their content back on demand. This is the second gap, and it is the one that catches the most technically literate teams, because the compliance features look like backup on an architecture diagram. Preservation and restoration solve different problems, and buying one while believing you own the other is how a firm arrives at an incident with no usable recovery option.

What Litigation Hold Actually Preserves

Litigation hold keeps mailbox content, including items a user deletes, discoverable for as long as the hold stands. Read favorably, that is real protection: content survives deletion, and eDiscovery can surface it. Read against, the retrieval experience is built for legal review, not operations. Recovering a working mailbox means running a search, exporting results, and reimporting them, often with folder structure and read state lost along the way. Neither reading is wrong. Hold answers “can we produce this in a dispute,” backup answers “can Sandra have her inbox back before her 10am.” Compliance-heavy teams should own both, a pattern we work through in Microsoft 365 management for professional services firms.

Retention Policies Versus a Second Copy

A retention policy can hold content for years, and on paper that closes the 93 day gap. In its favor, policy based retention is native, cheap, and applies tenant wide without agents. Against it, retention keeps data in the same tenant, under the same credentials, governed by the same admin accounts. A compromised global admin, or a policy edited by mistake, changes the fate of the original and the preserved copy together. Independence is the property that matters in a real incident, and retention does not provide it. That is the reasoning behind pairing native retention with an out of tenant copy, sometimes staged into Microsoft Azure cloud services the business already runs.

The Deleted User Account Trap

When an account is deleted, its OneDrive contents remain retrievable for a default window, commonly 30 days, before permanent removal. In practice that window collides with offboarding. Termination happens, the license gets reclaimed the same week to save money, and the manager who needed that user’s working files asks six weeks later. Nonprofits feel this hardest, where turnover is high and license budgets are watched closely, which is why the offboarding sequence gets its own section in our Microsoft 365 management for nonprofits guide. Reclaim the license after the files are secured, never before.

What a Granular Microsoft 365 Backup Guide Covers Per Workload

Restore granularity is the third gap, and it is the difference between a backup you can use during business hours and one you only touch during a disaster. Per workload behavior varies enough that a single blanket statement about “backing up Microsoft 365” tells you almost nothing about what you can recover on a Tuesday.

Exchange Online, Down to the Item

For mail, the standard worth holding a vendor to is item level restore into the original mailbox and folder, with read state and attachments intact, as of a chosen date. Anything coarser turns a two minute fix into a project. The common shortfall we find during an assessment is a product that restores a whole mailbox as a PST, which technically satisfies the checkbox and practically means somebody spends an afternoon in Outlook reattaching data by hand.

SharePoint and OneDrive, Structure Included

Document libraries carry more than files. Version history, metadata columns, permissions, and folder hierarchy are all part of the working artifact. A restore that returns the newest version of every file into a flat folder has technically recovered the bytes and functionally destroyed the site. Ask directly whether version history and library metadata survive the round trip, and ask to see it on a test site rather than in a datasheet. Teams running heavy document workflows, common across Microsoft 365 management for manufacturers, should treat this as the deciding question.

Teams, the Workload Everyone Underestimates

Teams is not one data store. Channel conversations live in a hidden group mailbox, files live in the connected SharePoint site, private chat messages live in individual mailboxes, and tabs and apps live in configuration. Products differ widely in how much of that they capture, and the gap usually shows up in chat history and channel structure. Confirm coverage store by store before assuming a Teams restore is a single operation, and revisit it whenever your tenant configuration changes during an Office 365 migration.

How to Test a Restore Instead of Assuming One

The fifth gap costs the most and takes the least effort to close: almost nobody tests the restore. A backup job reporting success proves data was written, not that it can be read back into a usable state. Our team treats an untested backup as an unverified claim, and a quarterly drill turns it into a measurement.

Run a Quarterly Restore Drill

Pick a real target, not a synthetic one. Restore one mailbox folder from 60 days ago, one document library with version history, and one Teams channel’s files. Time each from request to usable, and write the number down. Firms that do this find their real recovery time runs two to five times the vendor estimate, and they find it out on a quiet Thursday instead of during an incident.

Write Down the Numbers You Can Defend

Recovery point objective is how much data you accept losing, recovery time objective is how long you accept waiting. Both should come from your own drill, not a datasheet. Once they exist, the conversation with leadership changes from a technical debate about products into a business decision about acceptable loss, which is the conversation you want to be having. Our Microsoft 365 support team runs these drills with clients and keeps the evidence on file for auditors.

Frequently Asked Questions

Does Microsoft 365 include a backup?

Microsoft 365 includes retention and recycle bin features, not a customer facing backup with a guaranteed restore path. Microsoft’s own add on backup product and third party tools exist precisely because native retention expires. Treat native features as short term recovery and add a second copy for anything you must recover past the retention window.

How long does Microsoft 365 keep deleted files?

SharePoint and OneDrive hold deleted items for up to 93 days across the two stage recycle bin, and Exchange Online holds deleted mail in recoverable items for 14 days by default, extendable to 30 by an administrator. Deleted user OneDrive content is commonly held for 30 days after the account is removed. All three clocks start at deletion.

Is litigation hold the same as a backup?

Litigation hold preserves mailbox content for discovery, but it is not built for operational restore. Retrieval runs through search and export rather than a direct return to the user’s mailbox, and the content stays inside the same tenant and the same admin boundary. Preservation and restoration are separate capabilities.

What should an SMB back up first in Microsoft 365?

Start with Exchange Online mailboxes and the SharePoint sites carrying financial, client, and contract records, since those are the ones auditors and clients ask about. Add OneDrive for staff who work locally, then Teams once you have confirmed how much of it your tool captures.

How often should we test a Microsoft 365 restore?

Once a quarter is a workable floor for most small businesses, plus one test after any tenant change such as a migration or a new backup product. Restore a mailbox folder, a document library with version history, and a Teams channel’s files, and record the time each takes.

Where to Start This Week

Retention windows are the quiet risk in nearly every small business Microsoft 365 tenant, and closing them is not a large project. Confirm what your current retention actually covers per workload, find out whether anything sits outside those windows that the business would need in a dispute or an audit, then run one restore drill and write down the real recovery time. If the drill produces a number you would not want to defend in a leadership meeting, that is the finding, and it is a far better one to have on a Thursday than during an incident. Our team does this work with SMBs every week, from the first retention review through the second copy and the quarterly drill that keeps it honest. If you want a second set of eyes on where your tenant stands, book a free strategy call and we will walk your workloads with you.

Related Posts

Matt Rosenthal