Does Microsoft 365 Need a Separate Backup? What Microsoft Actually Protects

Microsoft replicates your data across datacentres, so offices assume it is backed up. Replication survives hardware failure, not a deleted mailbox.

Part of our guide to Microsoft 365 & Cloud.

Laptop on an office desk showing a cloud file list, with a second screen beside it
Quick answer

Yes, in almost every case. Microsoft guarantees the service stays available and your data stays replicated, but under its shared responsibility model protecting the contents is your job. Recycle bins and retention buy weeks or months, not years, so deletions found late are unrecoverable without a separate backup.

Key takeaways

  • Microsoft protects the platform from failing. It does not protect your files from being deleted, overwritten or encrypted.
  • Retention windows are measured in weeks and months. A problem found a year later is past every one of them.
  • The realistic threats are ordinary: a leaver's account removed, a synced folder wiped, a mailbox compromised.
  • A separate backup should cover Exchange, OneDrive, SharePoint and Teams, and be restorable item by item.
  • Test a restore before you need one. An untested backup is an assumption, not a safeguard.

What does Microsoft actually protect in Microsoft 365?

Microsoft operates what it calls a shared responsibility model, and the split matters more than most buyers realise. Microsoft is responsible for the service: keeping Exchange Online, SharePoint, OneDrive and Teams running, patched, and replicated across datacentres so that a failed disk or a datacentre problem does not lose your tenant. That part is genuinely excellent and there is no need to duplicate it.

You are responsible for the data inside it. Microsoft's commitment is that your files will still be there exactly as your organisation left them, which is precisely the problem when your organisation left them deleted. Replication faithfully copies a deletion to every datacentre in the set. It is not a time machine and was never designed as one.

This is not a gap Microsoft hides; it is written into the service documentation. The confusion comes from the word cloud, which people hear as safe.

  • Microsoft's job: uptime, infrastructure resilience, physical security, patching, replication.
  • Your job: who has access, what gets deleted, what gets shared, and whether you can get it back.

Is recycle bin and retention the same as a backup?

No, and this is where most offices are caught out. Microsoft 365 does include several recovery mechanisms, and for everyday mistakes they work well. A file deleted from SharePoint or OneDrive goes to a first-stage recycle bin, then a second-stage one, with Microsoft's published default giving a combined window of about 93 days. Deleted mail sits in Deleted Items, then in a recoverable items area for a configurable period. A removed user account can normally be restored within roughly 30 days.

Every one of those is a window, not an archive. They are designed for the deletion you notice on Tuesday afternoon, not the one you discover during an audit. Check your own tenant rather than trusting a general figure, because these defaults are configurable and Microsoft revises them.

Retention policies are a different tool again, and they are frequently mistaken for backup because they sound like one. A retention policy governs how long content must be kept and when it must be disposed of, usually for compliance reasons. It preserves content against deletion for a defined period, in place, in the same tenant, under the same administrator credentials. If that tenant is compromised or misconfigured, the retained copy is subject to the same event.

What actually goes wrong in a real office?

The scenarios that cost Dubai businesses data are rarely dramatic. They are administrative and they are quiet, which is exactly why the retention window has usually closed by the time anyone looks.

An employee leaves. Their licence is reclaimed to save money, the account is removed a few weeks later, and eight months on somebody needs the contract history that lived in their mailbox. A designer reorganises a synced OneDrive folder on their laptop, the sync client faithfully applies those deletions to the cloud, and the original structure is gone everywhere at once. A finance mailbox is compromised through a phishing link, and the attacker deletes the messages they sent from it to cover the trail.

None of these are Microsoft failing. In each case it did exactly what it promised and replicated the change reliably. The only question is whether you kept an independent copy the change could not reach.

  • Departing staff whose accounts are removed before anyone audits what was in them.
  • Sync clients propagating a local deletion or reorganisation to the cloud copy.
  • Ransomware encrypting files on a device, which then sync up as encrypted versions.
  • A compromised account deleting evidence, or a policy misconfigured by an administrator.
  • A dispute or investigation needing mail from two or three years ago.

What should a Microsoft 365 backup actually cover?

A backup worth paying for is independent of the tenant it protects and can restore a single item without restoring everything around it. That second point sounds minor until the day you need one folder back and the alternative is rolling an entire site collection backwards over the work everyone did since.

Coverage should span all four workloads, because data moves between them constantly. Teams catches people out: the conversations live in Exchange and the files in SharePoint, so a backup covering only mailboxes captures half of it.

  • Stored separately from the tenant, so a tenant-level compromise cannot reach it.
  • Restorable item by item, not only as a full rollback.
  • Retained for a period that matches your obligations, not a default 30 or 93 days.
  • Encrypted, with access limited to named administrators.
What to confirm a Microsoft 365 backup covers
WorkloadWhat is at riskWhat good coverage looks like
Exchange OnlineMail, calendar and contacts from closed or deleted accountsItem-level restore, including from accounts no longer licensed
OneDriveFiles wiped by a sync client or a departing employeePoint-in-time restore of a folder or single file with versions
SharePointDocument libraries, metadata, permissions and site structureRestore of libraries and permissions, not just loose files
TeamsChannel conversations, files, and the team structure itselfChats and channel files together, so context survives

How long should a Dubai business keep Microsoft 365 backups?

There is no single correct answer, and anyone who gives you one without asking about your business is guessing. The retention period should be driven by what you may be asked to produce and by how long a problem can plausibly go unnoticed.

Start with your obligations. UAE businesses commonly need to retain accounting and tax records for a defined number of years, and the current requirement should be confirmed with your accountant or legal adviser rather than assumed from a general article. Contracts and client correspondence may need to outlive the project that produced them. Employment records carry their own expectations.

Then add a practical margin. The deletions that hurt are the ones nobody notices, and nobody notices quickly. One year of retention covers far more real incidents than the defaults do; several years covers most disputes.

How do you know the backup actually works?

A backup that has never been restored is a belief, not a control. This is the most common weakness we find, and it is not neglect: the backup reports success every day and the dashboard is green, so there is no reason to doubt it until the day it matters.

Test by restoring something real. Pick a file, a folder and a mailbox item, restore each to an alternative location, and open them. Record the date, what was restored, how long it took and who did it. That record is what turns a subscription into evidence, and it is what an auditor or an insurer will ask to see.

Run the test on a schedule, and run it again after any significant change: a migration, a licensing change, a new backup product, or a change of IT provider. The principles here are the same ones in our guide to backup that actually restores, applied to a cloud tenant rather than a file server.

  • Restore to a separate location so you never overwrite live data during a test.
  • Include at least one item from an unlicensed or closed account.
  • Time the restore, so your recovery expectations are based on measurement.
  • Write down the result, with a date.

Does this replace security, or sit alongside it?

Alongside. A backup is what you fall back on when prevention has already failed, and treating it as a substitute for security is how offices end up restoring the same problem repeatedly.

The controls that stop most incidents are unglamorous and largely included in licences businesses already hold. Multi-factor authentication on every account closes off the compromised-mailbox route almost entirely. Limiting who holds Global Administrator reduces the blast radius of one mistake. A documented leaver process means accounts are archived deliberately rather than deleted to free a licence.

Backup is the layer underneath all of that. Our cybersecurity for small business in Dubai page covers the preventive side, and Microsoft 365 and cloud services covers configuring the tenant properly in the first place.

How Listonics handles Microsoft 365 backup

We start by looking at what your tenant is set to today, because it is common to find retention already configured in a way nobody remembers choosing. That review covers the current recycle bin and retention settings, which accounts are unlicensed or orphaned, whether MFA is genuinely enforced, and what a restore would involve right now.

From there we scope a backup that covers Exchange, OneDrive, SharePoint and Teams, with a retention period matched to what your business actually has to keep. We set it up, run a first restore test with you watching, and give you the written result. Ongoing, the restore test is part of the regular service rather than something that happens after an incident.

If you want to review where your Microsoft 365 data stands, a free office IT assessment covers it. You keep the findings either way, including administrator credentials and documentation.

Frequently asked questions

Microsoft backs up its own infrastructure so the service stays available, and replicates your data across datacentres to survive hardware failure. It does not keep an independent historical copy of your content for you to restore from. Under the shared responsibility model, protecting the data itself is the customer's responsibility.

Microsoft's published defaults give SharePoint and OneDrive a combined recycle bin window of around 93 days, and a deleted user account can normally be restored within about 30 days. These are configurable and can be changed, so confirm the settings in your own tenant rather than relying on a general figure.

No. A retention policy keeps content for a defined period inside the same tenant, mainly for compliance. A backup keeps an independent copy outside the tenant. If the tenant is compromised or misconfigured, retained content is exposed to the same event, whereas a separate backup is not.

No. Sync is designed to make every copy identical, so a deletion or an encryption on one device is faithfully applied everywhere else. Versioning helps with a small mistake caught quickly, but sync by design removes the independent copy that a backup depends on.

Yes. Those controls prevent incidents, which is where most of your effort should go, but they do not help with an accidental deletion, a departing employee's removed account, or a request for mail from three years ago. Prevention and recovery solve different problems.

Restore something and open it. Pick a file, a folder and a mailbox item, restore each to an alternative location, confirm they are intact, and write down the date and how long it took. A backup that reports success every night but has never been restored has not actually been verified.

Published Sep 20, 2026 · Last reviewed September 13, 2026 · 1,843 words

Talk to an engineer about microsoft 365 setup & cloud for your office.

contact us
Chat on WhatsApp