Microsoft doesn’t back up your mailbox, and the recycle bin is not a backup either
Ask an owner whether their email is backed up and most say yes, it is in the cloud. Ask them what happens if a bookkeeper deletes a folder of supplier invoices in March and nobody notices until August, and the answer changes.
About this piece
- Article
- Cloud & Microsoft 365
- Written by Nicholas Backwell · Founder, Redsilicon
- Updated 2026-08-24
Microsoft keeps your service running. It does not keep a copy of your data on your behalf, and the difference only becomes visible on the day you need something back.
The short version
- Microsoft’s job is uptime and infrastructure. Recovering your content after your own people delete it is your job.
- Deleted mail sits recoverable for a limited window measured in weeks, not years.
- Files in SharePoint and OneDrive follow their own separate clocks, and they are not the same as the mail clock.
- Ransomware that encrypts a synced OneDrive folder syncs the encrypted version up.
- An untested backup is a belief, not a control. Restore something before you need to.
What the shared responsibility model actually splits
Microsoft publishes a division of labour that most people never read. Simplified honestly, it goes like this.
Microsoft is responsible for the service being available, for the physical infrastructure, for replicating your data across their own datacentres so a hardware failure does not lose it, and for the platform’s own security.
You are responsible for your data. Who has access to it. What happens when somebody deletes it. Whether you can get a specific version of a specific file back from a specific date.
That replication point trips people up, so it is worth separating. Microsoft holding several copies of your mailbox protects against Microsoft losing a disk. It does not protect against a person emptying a folder, because all the copies faithfully reflect the deletion. Redundancy is not the same thing as recovery.
The retention windows nobody has read
Deleted items in Exchange Online go through two stages. First the Deleted Items folder, which a user can dig through themselves. Then, when emptied from there, a Recoverable Items area that holds them for a limited period before they are gone.
The exact number of days depends on your licence and whether an administrator has changed the default, which is precisely why “it is in the cloud somewhere” is not a plan. If you have never looked at your own tenant’s setting, you do not know what your window is.
Two situations blow straight through it.
Slow-discovery deletion. Someone tidied up a mail folder in spring. Nobody noticed until an auditor asked in autumn. Every retention window in Microsoft 365 is shorter than that gap.
A departing employee’s mailbox. When you remove the licence, the mailbox becomes inactive and eventually goes. If that person had five years of client correspondence, and nothing captured it, it goes with them. This is one reason the first week after someone leaves matters so much.
Files in SharePoint and OneDrive have their own recycle bins with their own periods, plus version history, plus a second-stage site collection recycle bin that an administrator can reach. Version history is genuinely useful and saves people constantly. It is also per file, which is no help when you need a whole library as it stood on a particular Tuesday.
Teams is the messiest of the lot, because Teams is not one thing. Chat messages live in mailboxes. Files posted in channels live in SharePoint. Recordings depend on where they were saved. Restoring a deleted Team is not one operation, it is several, and each follows the rules of whatever service is underneath.
The one that surprises people: sync carries the damage up
OneDrive syncing your desktop folders feels like a backup because a copy exists somewhere else. It is a mirror, and a mirror reflects whatever happens.
Ransomware encrypts the local files. The sync client sees changed files. It uploads them. Now the cloud copy is encrypted too.
Microsoft does provide a self-service restore that can roll OneDrive back to an earlier point, and it works. It is also bounded by a time limit and by version history existing on those files, and it is a per-library operation done under pressure while people are asking when they can work again. Useful. Not the same as having an independent copy.
This is the exact question your insurer is asking, incidentally. The public Canadian application forms ask about backups held “offline or on a separate network.” A mirror your production systems can write to does not meet that description. That is covered in more detail in what your renewal actually asks.
Retention policies are not backups, and legal hold is not either
Two features get sold as backup by people who should know better.
Retention policies control how long content is kept and when it is deleted. They can stop something being deleted permanently before a set period. They are built for compliance and discovery, not for restoring a folder structure to a point in time. Recovering from them means eDiscovery searches and exports, which is a job rather than a click.
Litigation hold preserves everything in a mailbox so it can be searched later. Same story. It is an evidence tool. Ask it to put a user’s mail folders back the way they were on 14 March and you are in for a long afternoon.
Both are worth having. Neither answers “restore this.”
What a real backup for Microsoft 365 looks like
A third-party backup takes an independent copy of your Exchange, SharePoint, OneDrive and Teams data and holds it somewhere Microsoft does not control, on a retention period you choose.
The features that matter when you are comparing options:
Retention you set. If you want seven years because of how long you keep client records, that should be a setting, not a negotiation.
Point-in-time restore. Being able to say “this mailbox as it was on this date” rather than hunting item by item.
Granular restore too. Because most real requests are one folder or one file, and you should not need a full restore for that.
Separate credentials. If the backup can be deleted by whoever compromises your Microsoft 365 global admin account, it is inside the blast radius. This is the point people miss most often.
A tested restore. Which is not a feature. It is something you do.
That last one is the whole thing. A backup nobody has restored from is a monthly charge and a feeling. Pick a real file, restore it to a different location, open it, confirm it is right. Once a quarter, in the calendar, ten minutes.
What this means for your building
A dental office in Whitby keeps records for years because it has to, and its practice management data usually lives in a separate system with its own backup. The gap is almost always email: referral correspondence, lab communication, patient messages, none of it captured anywhere.
A contractor in Bowmanville has the opposite shape. Everything of value is a photo, a quote or a signed change order, and most of it lives in OneDrive or in a job management system. The gap is that OneDrive is treated as the archive rather than the working copy, so there is no second copy of anything.
A professional services firm in Ajax has the highest exposure, because its entire product is documents and correspondence, and because turnover means mailboxes get closed regularly. Every departure is a potential permanent loss unless something captured that mailbox first.
What to do about it
Steps one through three cost nothing.
- Find out your actual deleted-item retention. Not the default from an article. Your tenant, your licence, your settings. If nobody can tell you the number, that is your answer.
- Write down your offboarding step for mailboxes. What happens to a mailbox when someone leaves, who does it, and how long is it kept. One paragraph.
- Try a restore. Pick a file deleted last month and see whether you can actually get it back and how long it takes. Do this on a quiet Tuesday, not during an incident.
- Decide your real retention requirement based on how long your business needs records, not on what a product offers by default.
- Add third-party backup covering Exchange, SharePoint, OneDrive and Teams, with credentials separate from your Microsoft 365 admin account.
- Put a quarterly test restore in the calendar with a name against it.
Steps four through six are what our Microsoft 365 work covers, usually alongside a tenant review that finds the sharing permissions nobody has looked at since setup.
Want this scoped for your site?
Tell us the building and what you’re trying to achieve. We’ll tell you what it takes, and whether you actually need it.
Before you call
We are eight people. Is this overkill?
Eight people generate the same irreplaceable correspondence as eighty, just less of it. The cost of backup scales with users, so at eight people it is small. The cost of losing a mailbox does not scale down at all.
Our IT provider says Microsoft handles it.
Ask them one question: if a user permanently deletes a folder and reports it four months later, what is the recovery path? If the answer involves Microsoft support, there isn’t one. That is a reasonable question and a good provider will not be offended by it.
Do we need this if we also have a server?
Different problem. Your server backup does not cover cloud mailboxes, and your cloud data does not cover the server. Businesses running both often have one covered properly and assume it covers the other.
What about Google Workspace?
Same structure, same gaps, same answer. The vendor keeps the service running. Recovering your content after your own people delete it is still yours.