← Blog

Who's Backing Up Your Microsoft 365 Data?

September 10, 2026 · 6 min read · Jim Johnson

An organization we assessed offboarded a departing employee the standard way: IT disabled the account, wiped the mailbox and OneDrive within the week, moved on. Three months later, finance needed a contract that employee had negotiated. It had lived in that mailbox. Nobody had put it anywhere else, and by the time anyone went looking, it was gone — not hidden, not archived, gone.

Nobody did anything wrong, exactly. They did what most organizations do. The assumption underneath it — Microsoft has this backed up somewhere — is the part that wasn't true.

Microsoft protects the platform. You own the data on it.

What Microsoft actually promises

This isn't a gap in the fine print. Microsoft states it directly. Its Services Agreement, effective 30 September 2025, puts the responsibility in plain language: organizations should "backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services." Not Microsoft's data. Yours, that you happen to store there.

Microsoft is very good at the half it owns — uptime, infrastructure, platform security, geographic redundancy so a data center failure doesn't take the service down. None of that is a promise to keep a recoverable copy of your mailbox, your SharePoint site, or your Teams history. That's the other half, and it's been assigned to you since before most people read the agreement.

What the recycle bin actually does — and when it stops

Here's the part that trips people up, because it looks like a safety net right up until it isn't one.

When a licensed user's account is deleted, Microsoft's documentation lays out the sequence exactly: the OneDrive data is retained for a default 30 days, configurable by the admin. A reminder email goes out 7 days before that window closes. After it closes, the OneDrive moves to a second-stage recycle bin — the site collection recycle bin — where it sits for another 93 days. After that, it's permanently deleted, unless a retention policy or an eDiscovery hold was already in place to stop the clock.

Add it up and the honest number is around four months from account deletion to gone-for-good, assuming nobody actively saved it first. Four months feels like a long time until the person who was supposed to notice has moved on to three other things, or never knew the countdown had started at all.

A recycle bin with a deadline is not a backup. It's a delay.

There's a second trap in the same documentation: an unlicensed or unpaid OneDrive account can be deleted after 12 months regardless of retention settings, retention policies, or holds. Losing a license — through an offboarding, a budget trim, a licensing cleanup — can quietly start a second clock that overrides the protections you thought were in place.

Three ways this actually bites

The departing-employee gap. The scenario above. The retention window looks generous until the day it isn't, because nobody assigned anyone to check it before day 120.

The mass-delete. A migration script, a bad automation, or a compromised admin account deletes at scale across SharePoint and OneDrive rather than one file at a time. Version history and the recycle bin are built around recovering individual items a person meant to keep, not reconstructing an environment after a wide, fast deletion.

The account that holds the safety net is the account under attack. Retention policies and legal holds live inside the same tenant they're meant to protect. If the credentials that manage those policies are the credentials an attacker compromises, the backstop you were counting on can be altered or turned off by the same person who caused the problem.

Retention and litigation hold are not backup either

These are useful tools, and worth having. They are not the same tool as backup, and the difference matters more than it sounds.

Retention keeps things where they already are. It doesn't give you a point-in-time copy you can restore to a known-good state. It doesn't protect data that lived outside the policy's scope. And it depends on the same tenant staying healthy — it's a rule enforced from inside the house, not a copy kept somewhere else.

Real backup means an independent copy, in storage separate from your Microsoft 365 tenant, with its own credentials, that a full compromise of your environment can't reach and a license change can't quietly expire.

What this actually looks like when it's done right

This is the part we can be specific about, because it's what we run. We back up Microsoft 365 with a dedicated backup platform, entirely separate from Microsoft's own retention tools — full Exchange mailboxes (inbox, folders, attachments, calendar, contacts), SharePoint site collections and document libraries, OneDrive files and folders, and Teams channel messages and files, all of it. The copy lives outside your Microsoft 365 tenant, so a compromise of the tenant doesn't reach it. Recovery runs at whatever grain the situation calls for — one email, one mailbox, one site — without touching anything that's still intact.

The tool matters less than the answers. Whoever handles this for you, the six questions above are what tell you whether it's actually covered. Ask us, or ask whoever handles it today, to answer them in writing before you assume the gap is closed.

What to ask for

Whoever handles this for you — us, your current provider, or your own IT team — ask to see these in writing.

  • Who owns Microsoft 365 backup, by name. Not "IT handles it." A person.
  • Whether it's actual third-party backup, or Microsoft's built-in retention being relied on as if it were one. Those are different tools with different guarantees.
  • Where the backup copies live, and whether they use separate storage and separate credentials from the tenant they're protecting.
  • What's covered, explicitly: mailboxes, OneDrive, SharePoint sites, Teams chats and channels, shared mailboxes, public folders. A list, not an assumption.
  • How long backup data itself is kept — and whether that's longer than the roughly four-month window built into Microsoft's own retention defaults.
  • The last time a restore was actually tested, what was restored, and how long it took. We wrote about why that question matters more than any other one in when did you last test a restore.

Why an IT company would tell you to do this yourself

Because every figure above comes from Microsoft's own public documentation, and anyone with admin access to your tenant can open the retention settings and see the same math we just walked through. None of it requires us, and the checklist works the same way regardless of which tool or provider ends up answering it — ours included. If you check and it turns out someone already has this covered properly, that's a genuinely good outcome — one worth finding out from a five-minute look, not from a deleted mailbox.

Everything above is yours to keep whether or not we ever speak again.

We're a veteran-owned team in the Denver metro, working with organizations in the 15-to-70 person range — nonprofits, professional services, and manufacturers. Senior engineers only, month-to-month, no multi-year lock-in. If you want the fuller picture of what a tested backup and recovery setup looks like, we cover it in when did you last test a restore, and the service itself is backup and disaster recovery.

So: if the next departure from your team happened today, does anyone know whether that person's mailbox is backed up, or just waiting out a 93-day clock?

Book a free IT risk review or call us at 720-794-0400.


Sources, checked 10 September 2026

  • Microsoft Services Agreement, effective 30 September 2025, section 6.b — customer backup responsibility.
  • Microsoft Learn, OneDrive retention and deletion (SharePoint documentation), last updated 23 June 2026 — 30-day default retention, 93-day site collection recycle bin, 7-day reminder email, 12-month unlicensed/unpaid storage deletion window.

Sound like your situation?

Start with a free IT risk review or a platform discovery & alignment call — 30 minutes, no strings.

Assess your technology maturity Book my free IT risk review →

Sound like your situation?

Start with a free IT risk review or a platform discovery & alignment call — 30 minutes, no strings.