CtrlShiftIT
Microsoft 365 Security

Microsoft 365 Backup for Small Business

Microsoft 365 is highly available — but availability is not backup. If a user deletes a SharePoint site, an attacker encrypts a mailbox, or retention policies expire on data you actually need, Microsoft will not restore it for you. This is what real backup looks like.

01

Microsoft protects the platform — you protect the data

Microsoft's shared-responsibility model is explicit: they guarantee the availability and security of the Microsoft 365 platform (servers, network, datacenter). You are responsible for the data inside it.

That means: if your tenant is compromised and an attacker deletes mailboxes, encrypts SharePoint files, or wipes Teams channels, Microsoft will not restore that data. The same applies to accidental deletion, departing-employee data loss, and retention-policy mistakes.

Microsoft protects

Platform uptime, network, datacenter security, software patching, geographic redundancy.

You protect

Mailbox content, SharePoint files, OneDrive files, Teams chats and channels, calendar items, contacts.

02

What Microsoft 365 protects vs what backup protects

Microsoft 365 includes native data-protection features. They are useful, but they are not backup:

  • Recycle Bin (90 days for SharePoint, 30 for OneDrive)A short window for self-service recovery of deleted files. Not protection against retention-policy expiry or admin deletion.
  • Versioning (SharePoint and OneDrive)Retains previous file versions. Useful for editing mistakes; useless against ransomware that encrypts all versions.
  • Retention policies (Microsoft Purview)Preserves data for a configured period. They are policy enforcement, not backup — they cannot do point-in-time restoration.
  • Litigation holdPreserves mailbox content for legal requirements. Cannot restore selectively to a different mailbox.
03

Why OneDrive sync is not a backup solution

OneDrive sync replicates files between your laptop and the cloud. If a file changes on either side, the change syncs to the other side — including deletion and ransomware encryption.

A workstation hit with ransomware will encrypt every synced OneDrive file. Within minutes, those encrypted versions are in OneDrive and on every other device synced to that user. The Recycle Bin may catch some, but not all — and not reliably.

04

Why the Microsoft 365 Recycle Bin cannot be trusted as backup

  • Time-bound30 days (OneDrive) or 93 days (SharePoint) before items are permanently deleted.
  • Admin-deletableA compromised admin can empty the Recycle Bin, removing the safety net.
  • No point-in-time restoreYou can recover items, but not roll a SharePoint site back to "how it looked Tuesday at 3pm."
  • No long-term retentionAnything older than the Recycle Bin window is gone — even if you discover the loss months later.
05

Common data-loss scenarios in SMB tenants

Departing employee

Mailbox deleted before contents were preserved; legitimate client communications gone.

Ransomware

OneDrive and SharePoint files encrypted across the tenant via a single compromised account.

Accidental SharePoint site deletion

A power user deletes a site collection believing it is unused. 91 days later, the data is gone forever.

Retention policy misconfiguration

A policy set to "delete after 1 year" accidentally applied to a critical library.

Account compromise + cleanup

Attacker deletes the trace of their activity by emptying Sent Items and the Recycle Bin.

Migration mistake

A tenant-to-tenant migration loses email headers or breaks calendar invites — restoration is impossible without backup.

06

What a real Microsoft 365 backup solution should protect

  • Exchange Online mailboxesEmail, calendar, contacts, tasks, mailbox rules, and folder structure. Including shared and resource mailboxes.
  • SharePoint sitesDocument libraries, lists, site structure, permissions, and metadata.
  • OneDrive for BusinessAll user OneDrive content, including version history.
  • TeamsChannel messages (yes, even private chats — verify your tool supports this), files, and channel-level data.
  • Public folders and group mailboxesOften forgotten in backup planning, but contain real business data.
07

What a verified restore actually looks like

A backup you have never restored is a hope, not a backup. A verified restore proves the backup is recoverable end-to-end:

  1. 1

    Pick a non-critical item

    A deleted file from last month, an archived mailbox, a Teams channel from a past project.

  2. 2

    Restore to an alternate location

    Never restore to production — restore to a recovery folder or a sandbox tenant so you do not overwrite live data.

  3. 3

    Verify the content

    Open the file, check the email body, confirm the calendar invites still link properly.

  4. 4

    Document the time

    Note how long the restore took. That number is your real RTO (Recovery Time Objective) — not the marketing number on the backup vendor's website.

  5. 5

    Repeat quarterly

    Tenants change. Restore procedures break. Quarterly verification keeps the backup honest.

08

How to choose a Microsoft 365 backup solution

  • CoverageConfirm it covers Exchange, SharePoint, OneDrive, Teams (channels and private chats), and groups.
  • Retention flexibilityDaily backups retained for at least 1 year. Some industries (legal, medical) need 7+ years.
  • Granular restorePer-item restore (single email, single file, single Teams message) — not just full-tenant rollback.
  • Air-gapped storageBackups stored outside your Microsoft 365 tenant. A compromised tenant cannot delete a separately-stored backup.
  • Canadian data residencyFor PHIPA/PIPEDA compliance, the backup vendor should offer Canadian storage regions.
  • Restore performanceVendor-reported RTO matters less than your own tested RTO. Ask for case studies.
09

How often backups should be tested

  • Monthly: spot restoresA single file or email, restored and verified.
  • Quarterly: full restore drillRestore a deleted mailbox or a SharePoint site to a sandbox. Time it. Document it.
  • Annually: tabletop exerciseWalk through a ransomware scenario with the team. Who calls who? When do you restore? How do you verify the restored data is clean?
10

Retention policies are not backup

A common source of confusion: Microsoft Purview retention policies preserve data for a configured period, but they are not point-in-time backup. They cannot restore a SharePoint site to a previous date. They cannot recover individual deleted files easily. They are designed for legal preservation, not operational recovery.

If your "backup strategy" is "we have retention policies on," you do not have backup — you have legal-hold infrastructure.

FAQ

Frequently Asked Questions

5 results
CoverageDoes Microsoft 365 include backup?

No. Microsoft includes data-protection features (Recycle Bin, versioning, retention policies, litigation hold) but explicitly does not offer point-in-time backup or restore. Their shared-responsibility documentation states this clearly.

PricingHow much does a third-party Microsoft 365 backup cost?

Typically $4–8 per user per month, depending on coverage, retention length, and vendor. For a 15-user SMB, that is roughly $1,000–1,500/year — a fraction of the cost of a single data-loss incident.

CoverageHow long should we retain Microsoft 365 backups?

For unregulated SMBs, 1–3 years is typical. For regulated industries (legal, medical, financial), the retention requirement may be 7+ years — check your specific regulatory obligations.

SecurityCan backup protect against ransomware?

Yes — if the backup is stored outside the tenant (air-gapped) and you can restore from a point in time before the attack. This is why backup vendor selection matters: a backup stored inside your compromised tenant is not really backup.

CoverageDo small businesses really need Microsoft 365 backup?

Yes. The most common SMB data-loss scenarios — accidental deletion, departing-employee mailbox cleanup, ransomware, retention misconfiguration — all happen at the same rates as in larger organizations. The data loss costs are proportionally larger for an SMB because there are fewer staff to absorb the disruption.