Email and data you can get back

A deleted file or a compromised mailbox shouldn't cost more than a few minutes. Independent backup of Microsoft 365 and your files makes recovery quick — and provable.

A solid steel cube beside an identical frosted glass cube

In short

A deleted file or a compromised mailbox should not cost more than a few minutes. Microsoft keeps the service running, but recovering your data is your responsibility. Native retention gives 30 days in Exchange and 93 in OneDrive, and neither is a backup.

It is a common myth that anything kept in Microsoft 365 is automatically safe. Microsoft keeps the service running. Recovering your data after an accidental deletion, a mailbox compromise or a ransomware hit is your responsibility.

That division is called the shared responsibility model, and it is written down. It is simply not read until the week somebody needs it.

What Microsoft covers, and what it does not

Microsoft protects the platform: data centre failure, hardware failure, service availability. If a disk dies in Dublin, that is their problem and you will not hear about it.

What sits on your side of the line:

  • Accidental deletion by a user
  • Deliberate deletion by someone with access
  • Ransomware encrypting files that then sync to the cloud
  • Retention policies misconfigured, or changed by someone who should not have
  • Compliance holds expiring
  • Account compromise leading to data destruction

Every one of those is a scenario where the data is gone and the service is working perfectly.

The numbers people get wrong

The default windows are shorter than most businesses assume.

Exchange Online holds deleted items for 30 days. The SharePoint and OneDrive recycle bins hold for 93 days. After that, the data is not in a slower tier or an archive. It is gone.

Thirty days sounds generous until you consider how these things are actually discovered. A departed employee's mailbox, a project folder nobody opened over the summer, a finance file needed for an audit. The gap between deletion and discovery is routinely longer than the retention window.

Retention is not backup

This is the distinction that costs the most, so it is worth being precise.

Retention is a policy mechanism. It keeps data for a defined period to satisfy compliance, records management and legal hold requirements. It is designed to stop data disappearing too early.

Backup is a recovery mechanism. It takes independent point-in-time copies you can restore from, selectively, to a chosen moment.

The practical differences matter:

  • Native retention offers no point-in-time restore of a mailbox. You cannot say "put this back as it was on the 3rd".
  • Retention offers no protection against the policy itself being changed. An attacker with administrative access can shorten retention and then delete. The native tooling will not stop that, because it is a legitimate administrative action.
  • Restoring at scale from native tooling is slow and manual, which matters enormously on the day you need thousands of items back rather than one.

What independent backup adds

A separate backup of Microsoft 365 gives you three things retention cannot.

Point-in-time recovery. Restore a mailbox, a site, a Teams channel or a single file to how it was at a chosen moment, which is what you need after ransomware or a bulk deletion.

Independence. The copy sits outside the tenant, so compromising the tenant does not compromise the backup. This is the property that matters most in a ransomware scenario, and it is the one native tooling cannot provide by definition.

Speed and granularity. Finding and restoring the right thing in minutes rather than working through an export.

Backups are only as good as the last restore test

An untested backup is a belief, not a control.

The failures we see are rarely the backup not running. They are restores that turn out to be slower than the business assumed, permissions that do not come back with the data, or a system that was silently excluded from the job eighteen months ago.

Testing restores on a schedule is the only way to know. It also gives you a real recovery time, which is the number the business actually needs when deciding how long it could survive without a given system.

The compliance angle

Under GDPR, availability and resilience of personal data is an explicit obligation, not merely good practice. For businesses in scope for NIS2, Article 21's ten minimum measures include business continuity and backup management, and Ireland's NCSC published guidance in July 2026 making clear these are board-level responsibilities.

"Microsoft has it" is not an answer to either.

What we do

For managed customers, independent backup of Microsoft 365 and your files is part of the service rather than an option. It is monitored, restores are tested, and the recovery times are documented so the business knows what they are before it needs them.

If you are not certain what would happen to your data in the scenarios above, get in touch or read about managed IT.

All field notes

Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.